Description
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8
are susceptible to a difficult to exploit Reflected Cross-Site Scripting
(XSS) vulnerability. Successful exploit requires the attacker to know
specific information about the target instance and trick a privileged
user into clicking a specially crafted link. This could allow the
attacker to view or modify configuration settings or add or modify user
accounts.
are susceptible to a difficult to exploit Reflected Cross-Site Scripting
(XSS) vulnerability. Successful exploit requires the attacker to know
specific information about the target instance and trick a privileged
user into clicking a specially crafted link. This could allow the
attacker to view or modify configuration settings or add or modify user
accounts.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19590 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a difficult to exploit Reflected Cross-Site Scripting (XSS) vulnerability. Successful exploit requires the attacker to know specific information about the target instance and trick a privileged user into clicking a specially crafted link. This could allow the attacker to view or modify configuration settings or add or modify user accounts. |
References
| Link | Providers |
|---|---|
| https://security.netapp.com/advisory/ntap-20240216-0013/ |
|
History
Thu, 24 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netapp
Netapp storagegrid |
|
| CPEs | cpe:2.3:a:netapp:storagegrid:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Netapp
Netapp storagegrid |
Status: PUBLISHED
Assigner: netapp
Published:
Updated: 2025-04-24T15:11:36.844Z
Reserved: 2024-01-03T19:45:25.346Z
Link: CVE-2024-21984
Updated: 2024-08-01T22:35:34.659Z
Status : Analyzed
Published: 2024-02-16T23:15:08.050
Modified: 2024-12-13T17:55:08.837
Link: CVE-2024-21984
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD