CVE-2020-10753
published 2020-06-26CVE-2020-10753: A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS…
PriorityP434medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
1.63%
73.7th percentile
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | ceph | < ceph 14.2.15-1 (bookworm) | ceph 14.2.15-1 (bookworm) |
| debian | ceph | < ceph 14.2.21-1 (bookworm) | ceph 14.2.21-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| linuxfoundation | ceph | < 14.2.21 | 14.2.21 |
| linuxfoundation | ceph | — | — |
| linuxfoundation | ceph | >= 0 < 14.2.15-1 | 14.2.15-1 |
| linuxfoundation | ceph | >= 0 < 14.2.15-1 | 14.2.15-1 |
| linuxfoundation | ceph | >= 0 < 14.2.15-1 | 14.2.15-1 |
| linuxfoundation | ceph | >= 0 < 14.2.15-1 | 14.2.15-1 |
| linuxfoundation | ceph | >= 0 < 10.2.11-0ubuntu0.16.04.3 | 10.2.11-0ubuntu0.16.04.3 |
| linuxfoundation | ceph | >= 0 < 12.2.13-0ubuntu0.18.04.4 | 12.2.13-0ubuntu0.18.04.4 |
| linuxfoundation | ceph | >= 0 < 15.2.7-0ubuntu0.20.04.2 | 15.2.7-0ubuntu0.20.04.2 |
| opensuse | leap | — | — |
| redhat | ceph | < 14.2.21 | 14.2.21 |
| redhat | ceph | >= 0 < 14.2.21-1 | 14.2.21-1 |
| redhat | ceph | >= 0 < 14.2.21-1 | 14.2.21-1 |
| redhat | ceph | >= 0 < 14.2.21-1 | 14.2.21-1 |
| redhat | ceph | >= 0 < 14.2.21-1 | 14.2.21-1 |
| redhat | ceph_storage | — | — |
| redhat | ceph_storage | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3rmw-wm6w-rmcr: A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14
ghsa_unreviewed·2022-05-24·CVSS 5.4
CVE-2021-3524 [MEDIUM] CWE-20 GHSA-3rmw-wm6w-rmcr: A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. In addition, the prior bug fix for CVE-2020-10753 did not account for the use of \r as a header separator, thus a new flaw has been created.
GHSA
GHSA-cggp-94xr-prm6: A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway)
ghsa_unreviewed·2022-05-24
CVE-2020-10753 [MEDIUM] CWE-113 GHSA-cggp-94xr-prm6: A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway)
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.
OSV
CVE-2021-3524: A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14
osv·2021-05-17·CVSS 6.5
CVE-2021-3524 [MEDIUM] CVE-2021-3524: A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. In addition, the prior bug fix for CVE-2020-10753 did not account for the use of \r as a header separator, thus a new flaw has been created.
OSV
ceph vulnerabilities
osv·2021-01-28·CVSS 7.5
CVE-2020-10736 [HIGH] ceph vulnerabilities
ceph vulnerabilities
Olle Segerdahl found that ceph-mon and ceph-mgr daemons did not properly
restrict access, resulting in gaining access to unauthorized resources. An
authenticated user could use this vulnerability to modify the configuration and
possibly conduct further attacks. (CVE-2020-10736)
Adam Mohammed found that Ceph Object Gateway was vulnerable to HTTP header
injection via a CORS ExposeHeader tag. An attacker could use this to gain access
or cause a crash. (CVE-2020-10753)
Ilya Dryomov found that Cephx authentication did not verify Ceph clients
correctly and was then vulnerable to replay attacks in Nautilus. An attacker
could use the Ceph cluster network to authenticate via a packet sniffer and
perform actions. This issue is a reintroduction of CVE-2018-1128.
(CVE-2020-2566
OSV
ceph vulnerabilities
osv·2020-09-22·CVSS 6.5
CVE-2020-10753 [MEDIUM] ceph vulnerabilities
ceph vulnerabilities
Adam Mohammed discovered that Ceph incorrectly handled certain CORS
ExposeHeader tags. A remote attacker could possibly use this issue to
preform an HTTP header injection attack. (CVE-2020-10753)
Lei Cao discovered that Ceph incorrectly handled certain POST requests with
invalid tagging XML. A remote attacker could possibly use this issue to
cause Ceph to crash, leading to a denial of service. This issue only
affected Ubuntu 18.04 LTS. (CVE-2020-12059)
Robin H. Johnson discovered that Ceph incorrectly handled certain S3
requests. A remote attacker could possibly use this issue to perform a
XSS attack. (CVE-2020-1760)
OSV
CVE-2020-10753: A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway)
osv·2020-06-26·CVSS 6.5
CVE-2020-10753 [MEDIUM] CVE-2020-10753: A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway)
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.
Red Hat
gateway: radosgw: CRLF injection
vendor_redhat·2021-04-15·CVSS 5.4
CVE-2021-3524 [MEDIUM] CWE-20 gateway: radosgw: CRLF injection
gateway: radosgw: CRLF injection
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. In addition, the prior bug fix for CVE-2020-10753 did not account for the use of \r as a header separator, thus a new flaw has been created.
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in t
Ubuntu
Ceph vulnerabilities
vendor_ubuntu·2021-01-28·CVSS 7.5
CVE-2020-10753 [HIGH] Ceph vulnerabilities
Title: Ceph vulnerabilities
Summary: Several security issues were fixed in Ceph.
Olle Segerdahl found that ceph-mon and ceph-mgr daemons did not properly
restrict access, resulting in gaining access to unauthorized resources. An
authenticated user could use this vulnerability to modify the configuration and
possibly conduct further attacks. (CVE-2020-10736)
Adam Mohammed found that Ceph Object Gateway was vulnerable to HTTP header
injection via a CORS ExposeHeader tag. An attacker could use this to gain access
or cause a crash. (CVE-2020-10753)
Ilya Dryomov found that Cephx authentication did not verify Ceph clients
correctly and was then vulnerable to replay attacks in Nautilus. An attacker
could use the Ceph cluster network to authenticate via a packet sniffer and
perform actions. Th
Debian
CVE-2021-3524: ceph - A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in ve...
vendor_debian·2021·CVSS 5.4
CVE-2021-3524 [MEDIUM] CVE-2021-3524: ceph - A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in ve...
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. In addition, the prior bug fix for CVE-2020-10753 did not account for the use of \r as a header separator, thus a new flaw has been created.
Scope: local
bookworm: resolved (fixed in 14.2.21-1)
bullseye: resolved (fixed in 14.2.21-1)
forky: resolved (fixed in 14.2.21-1)
sid: resolved (fixed in 14.2.21-1)
trixie: resolved (fixed in 14.2.21-1)
Ubuntu
Ceph vulnerabilities
vendor_ubuntu·2020-09-22·CVSS 5.4
CVE-2020-10753 [MEDIUM] Ceph vulnerabilities
Title: Ceph vulnerabilities
Summary: Several security issues were fixed in Ceph.
Adam Mohammed discovered that Ceph incorrectly handled certain CORS
ExposeHeader tags. A remote attacker could possibly use this issue to
preform an HTTP header injection attack. (CVE-2020-10753)
Lei Cao discovered that Ceph incorrectly handled certain POST requests with
invalid tagging XML. A remote attacker could possibly use this issue to
cause Ceph to crash, leading to a denial of service. This issue only
affected Ubuntu 18.04 LTS. (CVE-2020-12059)
Robin H. Johnson discovered that Ceph incorrectly handled certain S3
requests. A remote attacker could possibly use this issue to perform a
XSS attack. (CVE-2020-1760)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ceph: radosgw: HTTP header injection via CORS ExposeHeader tag
vendor_redhat·2020-06-25·CVSS 5.4
CVE-2020-10753 [MEDIUM] CWE-113 ceph: radosgw: HTTP header injection via CORS ExposeHeader tag
ceph: radosgw: HTTP header injection via CORS ExposeHeader tag
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made.
Statement: * Red Hat Ceph Storage (RHC
Debian
CVE-2020-10753: ceph - A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The ...
vendor_debian·2020·CVSS 5.4
CVE-2020-10753 [MEDIUM] CVE-2020-10753: ceph - A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The ...
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.
Scope: local
bookworm: resolved (fixed in 14.2.15-1)
bullseye: resolved (fixed in 14.2.15-1)
forky: resolved (fixed in 14.2.15-1)
sid: resolved (fixed in 14.2.15-1)
trixie: resolved (fixed in 14.2.15-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10753 ceph: radosgw: HTTP header injection via CORS ExposeHeader tag [fedora-all]
bugzilla·2020-06-25·CVSS 5.4
CVE-2020-10753 [MEDIUM] CVE-2020-10753 ceph: radosgw: HTTP header injection via CORS ExposeHeader tag [fedora-all]
CVE-2020-10753 ceph: radosgw: HTTP header injection via CORS ExposeHeader tag [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2020-10753 ceph: radosgw: HTTP header injection via CORS ExposeHeader tag
bugzilla·2020-05-27·CVSS 5.4
CVE-2020-10753 [MEDIUM] CVE-2020-10753 ceph: radosgw: HTTP header injection via CORS ExposeHeader tag
CVE-2020-10753 ceph: radosgw: HTTP header injection via CORS ExposeHeader tag
It was reported that "newline" character in the CORS xml configuration file in the ExposeHeader tag can lead to the header injection attack.
When the CORS request is made the response contain the injected header. Using newline characters injected into the HTTP headers, it is possible for the malicious user to add arbitrary headers such as Set-Cookie to set arbitrary cookies.
This impacts the RHCS RadosGW S3 API.
For example malicious user could create a publicly-accessible S3 bucket with such CORS configuration and anyone that accessed that bucket would have these headers injected.
Discussion:
Mitigation:
Mitigation for this issue is either not available or the currently available options do not meet the Red
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00062.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10753https://lists.debian.org/debian-lts-announce/2021/08/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFU7LXEL2UZE565FJBTY7UGH2O7ZUBVS/https://security.gentoo.org/glsa/202105-39https://usn.ubuntu.com/4528-1/http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00062.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10753https://lists.debian.org/debian-lts-announce/2021/08/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFU7LXEL2UZE565FJBTY7UGH2O7ZUBVS/https://security.gentoo.org/glsa/202105-39https://usn.ubuntu.com/4528-1/
2020-06-26
Published