Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticated attacker with low privileges to delete configuration data or deny access to some resources.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Vulnerability Type
N/A
Vulnerability Title
NetApp StorageGRID 安全漏洞
Vulnerability Description
NetApp StorageGRID是美国网络器械(NetApp)公司的一套对象存储解决方案。 NetApp StorageGRID 11.9.0.12之前版本和12.0.0.4之前版本存在安全漏洞,该漏洞源于配置了单点登录和Microsoft Entra ID时存在服务端请求伪造漏洞,可能导致低权限认证攻击者删除配置数据或拒绝访问资源。
CVSS Information
N/A
Vulnerability Type
N/A