PT-2022-4100 · Netapp · Storagegrid
Published
2022-08-09
·
Updated
2022-08-15
·
CVE-2022-23238
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
StorageGRID versions 11.6.0 through 11.6.0.2
Description
The issue is related to errors in information processing, which could allow a remote unauthenticated attacker to view limited metrics information and modify alert email recipients and content. This could potentially give an attacker unauthorized access to protected information or alter the content of alerts.
Recommendations
For StorageGRID versions 11.6.0 through 11.6.0.2, consider updating the Linux kernel to version 4.7.0 or later to mitigate the risk. Additionally, as a temporary workaround, restrict access to metrics information and alert configuration to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Storagegrid