CVE-2023-28372

A flaw exists in FlashBlade Purity (OE) Version 4.1.0 whereby a user with privileges to extend an object’s retention period can affect the availability of the object lock.
Configurations

Configuration 1 (hide)

cpe:2.3:a:purestorage:purity:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:54

Type Values Removed Values Added
References () https://support.purestorage.com/Pure_Storage_Technical_Services/Field_Bulletins/Security_Bulletins/Security_Bulletin_for_FlashBlade_Object_Store_Privileged_Access_Vulnerability_CVE-2023-28372 - Vendor Advisory () https://support.purestorage.com/Pure_Storage_Technical_Services/Field_Bulletins/Security_Bulletins/Security_Bulletin_for_FlashBlade_Object_Store_Privileged_Access_Vulnerability_CVE-2023-28372 - Vendor Advisory
CVSS v2 : unknown
v3 : 2.7
v2 : unknown
v3 : 6.5

20 Sep 2024, 15:35

Type Values Removed Values Added
CWE CWE-284

05 Oct 2023, 15:50

Type Values Removed Values Added
References (MISC) https://support.purestorage.com/Pure_Storage_Technical_Services/Field_Bulletins/Security_Bulletins/Security_Bulletin_for_FlashBlade_Object_Store_Privileged_Access_Vulnerability_CVE-2023-28372 - (MISC) https://support.purestorage.com/Pure_Storage_Technical_Services/Field_Bulletins/Security_Bulletins/Security_Bulletin_for_FlashBlade_Object_Store_Privileged_Access_Vulnerability_CVE-2023-28372 - Vendor Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:purestorage:purity:*:*:*:*:*:*:*:*
First Time Purestorage purity
Purestorage
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 2.7

02 Oct 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-02 23:15

Updated : 2024-11-21 07:54


NVD link : CVE-2023-28372

Mitre link : CVE-2023-28372

CVE.ORG link : CVE-2023-28372


JSON object : View

Products Affected

purestorage

  • purity
CWE
NVD-CWE-noinfo CWE-284

Improper Access Control