Database/Control plane, storage & DevOps
NetApp ONTAP 9 role-based access control: A user holding several remote accounts with different roles performs actions
CVSS 7.6CVE-2024-21985Control plane, storage & DevOpscurated
Impact
A user holding several remote accounts with different roles performs actions none of those roles should permit, which defeats the separation between an operator who can read and one who can destroy.
Who can reach it
An authenticated ONTAP user with more than one remote account on a system below 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 or 9.13.1P4.
What to do
Upgrade to the fixed patch level. In the meantime, avoid granting the same person multiple ONTAP accounts with different roles, since that is the precondition.
References
Related entries
- HashiCorp Nomad Enterprise: Jobs using the policy-override option bypass mandatory Sentinel policiesCVE-2025-3744 · HashiCorp Nomad EnterpriseHigh
- Grafana: Client path traversal + open redirectCVE-2025-4123 · GrafanaHigh
- Sidero Omni: Reader role can read the full CA secrets bundle of an imported Talos clusterCVE-2026-45726 · Sidero Omni (ImportedClusterSecrets resource access rules)High
- rsync SSL modes: server TLS certificates are not validated, so an on-path attacker can read the transferCVE-2026-70454 · rsync (openssl mode) and rsync-ssl (stunnel mode) TLS server certificate validationHigh
- Red Hat Ansible Automation Platform automation-controller (custom Credential Type env injector): The custom CredentialCVE-2026-84706 · Red Hat Ansible Automation Platform automation-controller (custom Credential Type env injector)High
- OpenZFS (sharenfs export generation): When an NFS share is exported to IPv6 addresses via sharenfs, OpenZFS silentlyCVE-2013-20001 · OpenZFS (sharenfs export generation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.