Vulnerabilities > Purestorage > Purity > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-10-02 CVE-2023-31042 Unspecified vulnerability in Purestorage Purity
A flaw exists in FlashBlade Purity whereby an authenticated user with access to FlashBlade’s object store protocol can impact the availability of the system’s data access and replication protocols.
network
low complexity
purestorage
4.3
2017-10-11 CVE-2017-7352 Cross-site Scripting vulnerability in Purestorage Purity 4.7.5
Stored Cross-site scripting (XSS) vulnerability in Pure Storage Purity 4.7.5 allows remote authenticated users to inject arbitrary web script or HTML via the "host" parameter on the 'System > Configuration > SNMP > Add SNMP Trap Manager' screen.
network
low complexity
purestorage CWE-79
5.4