CVE-2021-32508: medium-severity vulnerability in QSAN Storage Manager
QSAN Storage Manager - UNIX Symbolic Link (Symlink) Following via FileStreaming function
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
A flaw in QSAN Storage Manager allows authenticated users to read any file on the system by manipulating file paths with symbolic links. An attacker who has login access can exploit this to view sensitive files they shouldn't have permission to access.
Absolute path traversal vulnerability in the FileStreaming function allows authenticated remote attackers to bypass access controls via symbolic link injection through the URL path parameter. The vulnerability requires valid authentication credentials and enables arbitrary file disclosure on the affected system.
In the same product, most dangerous first.