DSA-2022-259: Dell Container Storage Modules Security Update for Multiple Vulnerabilities

Summary: Dell Container Storage Modules remediation is available for gofsutil that may be exploited by malicious users to compromise the affected system.

Αυτό το άρθρο ισχύει για Αυτό το άρθρο δεν ισχύει για Αυτό το άρθρο δεν συνδέεται με κάποιο συγκεκριμένο προϊόν. Δεν προσδιορίζονται όλες οι εκδόσεις προϊόντων σε αυτό το άρθρο.

Impact

High

Details

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2022-34427 Dell Container Storage Modules 1.3 contains an operating system command injection in gofsutil library. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to run arbitrary operating system commands on the affected system.  8.8  CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2022-34426
Dell Container Storage Modules 1.3 contains a path traversal vulnerability in gofsutil library. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability leading to unintentional access to a path outside of restricted directory. 8.8  CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2022-34427 Dell Container Storage Modules 1.3 contains an operating system command injection in gofsutil library. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to run arbitrary operating system commands on the affected system.  8.8  CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2022-34426
Dell Container Storage Modules 1.3 contains a path traversal vulnerability in gofsutil library. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability leading to unintentional access to a path outside of restricted directory. 8.8  CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Επηρεαζόμενα προϊόντα και αποκατάσταση

CVEs Addressed  Product Affected Versions Updated Version Link to Update
CVE-2022-34427 Dell Container Storage Modules Versions 1.9 and earlier 1.10.0 https://github.com/dell/gofsutil  
CVE-2022-34426
CVEs Addressed  Product Affected Versions Updated Version Link to Update
CVE-2022-34427 Dell Container Storage Modules Versions 1.9 and earlier 1.10.0 https://github.com/dell/gofsutil  
CVE-2022-34426

Revision History

RevisionDateDescription
1.02022-09-15Initial Release

Related Information

Επηρεαζόμενα προϊόντα

Container Storage Modules, Product Security Information
Ιδιότητες άρθρου
Article Number: 000203352
Article Type: Dell Security Advisory
Τελευταία τροποποίηση: 18 Σεπ 2025
Βρείτε απαντήσεις στις ερωτήσεις σας από άλλους χρήστες της Dell
Υπηρεσίες υποστήριξης
Ελέγξτε αν η συσκευή σας καλύπτεται από τις Υπηρεσίες υποστήριξης.