are susceptible to a difficult to exploit Reflected Cross-Site Scripting
(XSS) vulnerability. Successful exploit requires the attacker to know
specific information about the target instance and trick a privileged
user into clicking a specially crafted link. This could allow the
attacker to view or modify configuration settings or add or modify user
accounts.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19590 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a difficult to exploit Reflected Cross-Site Scripting (XSS) vulnerability. Successful exploit requires the attacker to know specific information about the target instance and trick a privileged user into clicking a specially crafted link. This could allow the attacker to view or modify configuration settings or add or modify user accounts. |
| Link | Providers |
|---|---|
| https://security.netapp.com/advisory/ntap-20240216-0013/ |
|
Thu, 24 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netapp
Netapp storagegrid |
|
| CPEs | cpe:2.3:a:netapp:storagegrid:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Netapp
Netapp storagegrid |
Status: PUBLISHED
Assigner: netapp
Published:
Updated: 2025-04-24T15:11:36.844Z
Reserved: 2024-01-03T19:45:25.346Z
Link: CVE-2024-21984
Updated: 2024-08-01T22:35:34.659Z
Status : Analyzed
Published: 2024-02-16T23:15:08.050
Modified: 2024-12-13T17:55:08.837
Link: CVE-2024-21984
No data.
OpenCVE Enrichment
No data.
EUVD