📦 Storagegrid

by Netapp

🔍 What is Storagegrid?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-25291

CRITICAL CVSS 9.8 Mar 12, 2025

CVE-2025-25291 is an authentication bypass vulnerability in ruby-saml that allows attackers to bypass SAML single sign-on authentication via signature wrapping attacks. The vulnerability stems from pa...

CVE-2022-23806

CRITICAL CVSS 9.1 Feb 11, 2022

This vulnerability in Go's elliptic curve cryptography library allows Curve.IsOnCurve to incorrectly return true for invalid field elements. This could enable cryptographic bypass attacks where invali...

CVE-2021-39275

CRITICAL CVSS 9.8 Sep 16, 2021

CVE-2021-39275 is a critical buffer overflow vulnerability in Apache HTTP Server's ap_escape_quotes() function that could allow remote code execution or denial of service. The vulnerability affects Ap...

CVE-2025-26515

HIGH CVSS 7.5 Sep 19, 2025

An unauthenticated attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability in StorageGRID to change passwords for Grid Manager or Tenant Manager users when Single Sign-on is disabled. ...

CVE-2022-38734

HIGH CVSS 7.5 Mar 2, 2023

CVE-2022-38734 is a Denial of Service vulnerability in NetApp StorageGRID's Local Distribution Router service. Attackers can crash the LDR service by sending specially crafted requests, disrupting sto...

CVE-2022-0778

HIGH CVSS 7.5 Mar 15, 2022

CVE-2022-0778 is a denial-of-service vulnerability in OpenSSL's BN_mod_sqrt() function that can cause infinite loops when parsing specially crafted certificates or private keys containing invalid elli...

CVE-2022-23233

HIGH CVSS 7.5 Mar 4, 2022

This vulnerability in NetApp StorageGRID allows attackers to cause a Denial of Service (DoS) by targeting the Local Distribution Router (LDR) service. Successful exploitation could disrupt grid operat...

CVE-2022-23772

HIGH CVSS 7.5 Feb 11, 2022

CVE-2022-23772 is an integer overflow vulnerability in Go's math/big.Rat.SetString function that allows attackers to trigger uncontrolled memory consumption (denial of service) by providing specially ...

CVE-2021-36160

HIGH CVSS 7.5 Sep 16, 2021

CVE-2021-36160 is an out-of-bounds read vulnerability in Apache HTTP Server's mod_proxy_uwsgi module. A specially crafted URI path can cause the server to read beyond allocated memory boundaries, lead...

CVE-2021-3450

HIGH CVSS 7.4 Mar 25, 2021

This OpenSSL vulnerability allows certificate chain validation to be bypassed when the X509_V_FLAG_X509_STRICT flag is explicitly set. It affects applications using OpenSSL 1.1.1h-1.1.1j that enable s...

CVE-2025-26514

MEDIUM CVSS 6.4 Sep 19, 2025

This is a reflected cross-site scripting (XSS) vulnerability in NetApp StorageGRID that allows attackers to execute malicious scripts in a privileged user's browser session. It affects StorageGRID ver...

CVE-2025-26517

MEDIUM CVSS 5.4 Sep 19, 2025

This CVE describes a privilege escalation vulnerability in NetApp StorageGRID where authenticated attackers can discover Grid node names and IP addresses or modify Storage Grades. The vulnerability af...

CVE-2024-21994

MEDIUM CVSS 4.3 Nov 8, 2024

This vulnerability allows authenticated attackers to cause a Denial of Service (DoS) by crashing StorageGRID services. It affects StorageGRID (formerly StorageGRID Webscale) installations running vers...

CVE-2024-21988

MEDIUM CVSS 5.3 Jun 14, 2024

This vulnerability in NetApp StorageGRID allows attackers to potentially intercept and decrypt SSH communications through man-in-the-middle attacks. It affects StorageGRID versions before 11.7.0.9 and...