Known Vulnerabilities for Storagegrid by Netapp
Listed below are 10 of the newest known vulnerabilities associated with "Storagegrid" by "Netapp".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-23806 | Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations wi... | 9.1 - CRITICAL | 2022-02-11 | 2023-04-20 |
| CVE-2022-23773 | cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. Th... | 7.5 - HIGH | 2022-02-11 | 2023-08-08 |
| CVE-2022-23772 | Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory ... | 7.5 - HIGH | 2022-02-11 | 2022-11-09 |
| CVE-2022-23238 | Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kerne... | 6.5 - MEDIUM | 2022-08-10 | 2022-08-15 |
| CVE-2022-23233 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successful... | 7.5 - HIGH | 2022-03-04 | 2022-03-11 |
| CVE-2022-23232 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successful... | 4.9 - MEDIUM | 2022-03-04 | 2023-08-08 |
| CVE-2021-3450 | The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is... | 7.4 - HIGH | 2021-03-25 | 2023-11-07 |
| CVE-2021-3449 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 r... | 5.9 - MEDIUM | 2021-03-25 | 2023-11-07 |
| CVE-2021-3115 | Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using... | 7.5 - HIGH | 2021-01-26 | 2023-11-07 |
| CVE-2021-3114 | In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an underflo... | 6.5 - MEDIUM | 2021-01-26 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Netapp | Storagegrid | 9.0.4 | All | All | All |
| Application | Netapp | Storagegrid | 9.0.2 | All | All | All |
| Application | Netapp | Storagegrid | 9.0.1 | All | All | All |
| Application | Netapp | Storagegrid | 9.0.0 | All | All | All |
| Application | Netapp | Storagegrid | 11.3.0.4 | All | All | All |
| Application | Netapp | Storagegrid | 11.3 | All | All | All |
| Application | Netapp | Storagegrid | 11.2.0.8 | All | All | All |
| Application | Netapp | Storagegrid | 10.0.0 | All | All | All |