Описание
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary metrics queries, revealing metric results that they do not have access to.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 11.9.0.13 (исключая)Версия от 12.0 (включая) до 12.0.0.6 (исключая)
Одно из
cpe:2.3:a:netapp:storagegrid:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:storagegrid:*:*:*:*:*:*:*:*
EPSS
Процентиль: 8%
0.00184
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 4.3
github
5 месяцев назад
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary metrics queries, revealing metric results that they do not have access to.
EPSS
Процентиль: 8%
0.00184
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-200