CVE-2020-4381
published 2020-08-19CVE-2020-4381: IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.6 could allow an authenticated user to cause a denial of service during deployment or…
PriorityP427medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.00%
59.3th percentile
IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.6 could allow an authenticated user to cause a denial of service during deployment or upgrade if GUI specific services are enabled. IBM X-Force ID: 179162.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | elastic_storage_server | — | — |
| ibm | elastic_storage_server | — | — |
| ibm | elastic_storage_server | 5.3.0 – 5.3.6 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2gg9-xrg4-cvq2: IBM Spectrum Scale for IBM Elastic Storage Server 5
ghsa_unreviewed·2022-05-24
CVE-2020-4381 [LOW] GHSA-2gg9-xrg4-cvq2: IBM Spectrum Scale for IBM Elastic Storage Server 5
IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.6 could allow an authenticated user to cause a denial of service during deployment or upgrade if GUI specific services are enabled. IBM X-Force ID: 179162.
OSV
python-django vulnerabilities
osv·2020-06-04·CVSS 5.9
CVE-2020-13254 python-django vulnerabilities
python-django vulnerabilities
USN-4381-1 fixed several vulnerabilities in Django. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Dan Palmer discovered that Django incorrectly validated memcached cache
keys. A remote attacker could possibly use this issue to cause a denial of
service and obtain sensitive information. (CVE-2020-13254)
Jon Dufresne discovered that Django incorrectly encoded query parameters
for the admin ForeignKeyRawIdWidget. A remote attacker could possibly use
this issue to perform XSS attacks. (CVE-2020-13596)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-08-19
Published