CVE Vulnerabilities

CVE-2021-21528

Exposure of Information Through Directory Listing

Published: Nov 12, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Dell EMC PowerScale OneFS versions 9.1.0, 9.2.0.x, 9.2.1.x contain an Exposure of Information through Directory Listing vulnerability. This vulnerability is triggered when upgrading from a previous versions.

Weakness

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Affected Software

NameVendorStart VersionEnd Version
Emc_powerscale_onefsDell9.1.0.0 (including)9.1.0.0 (including)
Emc_powerscale_onefsDell9.2.0.0 (including)9.2.0.0 (including)
Emc_powerscale_onefsDell9.2.1.0 (including)9.2.1.0 (including)

Potential Mitigations

References