MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 16 h ago, last 16 h ago, peak #8

Dell patches two CVSS 10.0 flaws in Kubernetes storage software

Original: 🤖 Dell patches two max-severity (CVSS 10.0) flaws in Container Storage Modules (CSM) Authorization v2.4.0, which connect

Dell has released Container Storage Modules Authorization v2.4.0 to fix two maximum-severity flaws, both rated CVSS 10.0, in the software that connects Dell storage arrays to Kubernetes clusters. The bugs stem from missing authentication, allowing unauthenticated remote attackers to retrieve backend admin credentials across all tenants. Security teams running Dell storage with Kubernetes are urged to update immediately, as the flaws expose sensitive credentials without requiring valid accounts.

Why now: Maximum-severity flaws allowing credential theft across all tenants are an urgent patch priority for anyone running Dell storage with Kubernetes.

DellContainer Storage ModulesKubernetes

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/749828