Dell patches six critical flaws in Container Storage Modules for Kubernetes
Dell released fixes for six critical-severity vulnerabilities affecting its Container Storage Modules (CSM), which link enterprise storage arrays like PowerStore, PowerScale, PowerFlex, PowerMax and Unity XT to Kubernetes clusters. Two of the flaws, found in the CSM Authorization module, let unauthenticated attackers obtain admin credentials and full control over storage infrastructure; the other four allow root access on cluster nodes, token forgery, proxy takeover, and unauthorized access to Kubernetes Secrets. Dell is urging customers to upgrade to CSM version 1.18.0 or later as soon as possible.