First published: Fri Mar 19 2021(Updated: )
Cloud Manager versions prior to 3.9.4 contain an insecure Cross-Origin Resource Sharing (CORS) policy which could allow a remote attacker to interact with Cloud Manager.
Credit: security-alert@netapp.com
Affected Software | Affected Version | How to fix |
---|---|---|
NetApp Cloud Manager | <3.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-26991.
The title of this vulnerability is 'Cloud Manager versions prior to 3.9.4 contain an insecure Cross-Origin Resource Sharing (CORS) policy'.
The severity of CVE-2021-26991 is high with a severity value of 7.5.
Cloud Manager versions prior to 3.9.4 are affected by CVE-2021-26991.
This vulnerability can be exploited by a remote attacker to interact with Cloud Manager.
Yes, updating to Cloud Manager version 3.9.4 or later fixes this vulnerability.
You can find more information about CVE-2021-26991 at the following link: https://security.netapp.com/advisory/NTAP-20210318-0002.