CVE-2020-10753

Severity
6.5MEDIUM
EPSS
0.4%
top 38.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 26
Latest updateMay 24

Description

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages8 packages

NVDlinuxfoundation/ceph< 14.2.21
NVDredhat/ceph_storage3.0, 4.0+1
CVEListV5red_hat/red_hat_ceph_storageversions 3.x and 4.x
Debianceph< 14.2.15-1+3
Ubuntuceph< 10.2.11-0ubuntu0.16.04.3+2

Also affects: Fedora 32, Ubuntu Linux 16.04, 18.04

Patches

🔴Vulnerability Details

5
GHSA
GHSA-cggp-94xr-prm6: A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway)2022-05-24
OSV
ceph vulnerabilities2021-01-28
OSV
ceph vulnerabilities2020-09-22
OSV
CVE-2020-10753: A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway)2020-06-26
CVEList
CVE-2020-10753: A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway)2020-06-26

📋Vendor Advisories

5
Red Hat
gateway: radosgw: CRLF injection2021-04-15
Ubuntu
Ceph vulnerabilities2021-01-28
Ubuntu
Ceph vulnerabilities2020-09-22
Red Hat
ceph: radosgw: HTTP header injection via CORS ExposeHeader tag2020-06-25
Debian
CVE-2020-10753: ceph - A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The ...2020

💬Community

2
Bugzilla
CVE-2020-10753 ceph: radosgw: HTTP header injection via CORS ExposeHeader tag [fedora-all]2020-06-25
Bugzilla
CVE-2020-10753 ceph: radosgw: HTTP header injection via CORS ExposeHeader tag2020-05-27