CVE Vulnerabilities

CVE-2021-21594

Use of HTTP Request With Sensitive Query String

Published: Aug 16, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Dell PowerScale OneFS versions 8.2.2 - 9.1.0.x contain a use of get request method with sensitive query strings vulnerability. It can lead to potential disclosure of sensitive data. Dell recommends upgrading at your earliest opportunity.

Weakness

The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.

Affected Software

NameVendorStart VersionEnd Version
Emc_powerscale_onefsDell9.0.0.0 (including)9.1.0 (including)
Emc_powerscale_onefsDell8.2.2 (including)8.2.2 (including)

Potential Mitigations

References