Vulnerability Description
Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.0 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to view limited metrics information and modify alert email recipients and content.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netapp | Storagegrid | >= 11.6.0, < 11.6.0.3 |
| Canonical | Ubuntu Linux | 16.04 |
| Centos | Centos | 7.9 |
| Linux | Linux Kernel | < 4.7 |
| Redhat | Enterprise Linux Server | 7.9 |
References
- https://security.netapp.com/advisory/NTAP-20220808-0001/PatchVendor Advisory
- https://security.netapp.com/advisory/NTAP-20220808-0001/PatchVendor Advisory
FAQ
What is CVE-2022-23238?
CVE-2022-23238 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.0 are susceptible to a vulnerability which could al...
How severe is CVE-2022-23238?
CVE-2022-23238 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-23238?
Check the references section above for vendor advisories and patch information. Affected products include: Netapp Storagegrid, Canonical Ubuntu Linux, Centos Centos, Linux Linux Kernel, Redhat Enterprise Linux Server.