CVE-2020-10753
published 2020-06-26CVE-2020-10753: A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS…
medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | ceph | < ceph 14.2.15-1 (bookworm) | ceph 14.2.15-1 (bookworm) |
| debian | ceph | < ceph 14.2.21-1 (bookworm) | ceph 14.2.21-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| linuxfoundation | ceph | < 14.2.21 | 14.2.21 |
| linuxfoundation | ceph | — | — |
| linuxfoundation | ceph | >= 0 < 14.2.15-1 | 14.2.15-1 |
| linuxfoundation | ceph | >= 0 < 14.2.15-1 | 14.2.15-1 |
| linuxfoundation | ceph | >= 0 < 14.2.15-1 | 14.2.15-1 |
| linuxfoundation | ceph | >= 0 < 14.2.15-1 | 14.2.15-1 |
| linuxfoundation | ceph | >= 0 < 10.2.11-0ubuntu0.16.04.3 | 10.2.11-0ubuntu0.16.04.3 |
| linuxfoundation | ceph | >= 0 < 12.2.13-0ubuntu0.18.04.4 | 12.2.13-0ubuntu0.18.04.4 |
| linuxfoundation | ceph | >= 0 < 15.2.7-0ubuntu0.20.04.2 | 15.2.7-0ubuntu0.20.04.2 |
| opensuse | leap | — | — |
| redhat | ceph | < 14.2.21 | 14.2.21 |
| redhat | ceph | >= 0 < 14.2.21-1 | 14.2.21-1 |
| redhat | ceph | >= 0 < 14.2.21-1 | 14.2.21-1 |
| redhat | ceph | >= 0 < 14.2.21-1 | 14.2.21-1 |
| redhat | ceph | >= 0 < 14.2.21-1 | 14.2.21-1 |
| redhat | ceph_storage | — | — |
| redhat | ceph_storage | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv7.5HIGH