CVE-2021-42079: SSRF vulnerability in OSNEXUS QuantaStor before 6.0.0.355
An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack. This is exclusively with POST requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-42079?
CVE-2021-42079 is a vulnerability that allows an authenticated administrator to prepare an alert that can execute a Server-Side Request Forgery (SSRF) attack exclusively with POST requests.
What software is affected by CVE-2021-42079?
Osnexus Quantastor up to version 6.0.0.355 is affected by CVE-2021-42079.
How severe is CVE-2021-42079?
CVE-2021-42079 has a severity rating of medium (4/10).
How can I fix CVE-2021-42079?
To fix CVE-2021-42079, apply the necessary updates or patches provided by Osnexus Quantastor.
Where can I find more information about CVE-2021-42079?
You can find more information about CVE-2021-42079 at the following references: [https://www.divd.nl/DIVD-2021-00020](https://www.divd.nl/DIVD-2021-00020), [https://www.wbsec.nl/osnexus](https://www.wbsec.nl/osnexus), [https://www.osnexus.com/products/software-defined-storage](https://www.osnexus.com/products/software-defined-storage).