CVE-2020-1760
published 2020-04-23CVE-2020-1760: A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.52%
71.9th percentile
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | ceph | < ceph 14.2.9-1 (bookworm) | ceph 14.2.9-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| linuxfoundation | ceph | < 14.2.21 | 14.2.21 |
| linuxfoundation | ceph | >= 0 < 14.2.9-1 | 14.2.9-1 |
| linuxfoundation | ceph | >= 0 < 14.2.9-1 | 14.2.9-1 |
| linuxfoundation | ceph | >= 0 < 14.2.9-1 | 14.2.9-1 |
| linuxfoundation | ceph | >= 0 < 14.2.9-1 | 14.2.9-1 |
| linuxfoundation | ceph | >= 0 < 10.2.11-0ubuntu0.16.04.3 | 10.2.11-0ubuntu0.16.04.3 |
| linuxfoundation | ceph | >= 0 < 12.2.13-0ubuntu0.18.04.4 | 12.2.13-0ubuntu0.18.04.4 |
| redhat | ceph_storage | — | — |
| redhat | ceph_storage | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.5MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
vendor_ubuntu5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gj74-48rr-85f7: A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3
ghsa_unreviewed·2022-05-24
CVE-2020-1760 [MEDIUM] CWE-79 GHSA-gj74-48rr-85f7: A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
OSV
ceph vulnerabilities
osv·2020-09-22·CVSS 6.5
CVE-2020-10753 [MEDIUM] ceph vulnerabilities
ceph vulnerabilities
Adam Mohammed discovered that Ceph incorrectly handled certain CORS
ExposeHeader tags. A remote attacker could possibly use this issue to
preform an HTTP header injection attack. (CVE-2020-10753)
Lei Cao discovered that Ceph incorrectly handled certain POST requests with
invalid tagging XML. A remote attacker could possibly use this issue to
cause Ceph to crash, leading to a denial of service. This issue only
affected Ubuntu 18.04 LTS. (CVE-2020-12059)
Robin H. Johnson discovered that Ceph incorrectly handled certain S3
requests. A remote attacker could possibly use this issue to perform a
XSS attack. (CVE-2020-1760)
OSV
CVE-2020-1760: A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3
osv·2020-04-23·CVSS 6.1
CVE-2020-1760 [MEDIUM] CVE-2020-1760: A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
Ubuntu
Ceph vulnerabilities
vendor_ubuntu·2020-09-22·CVSS 5.4
CVE-2020-10753 [MEDIUM] Ceph vulnerabilities
Title: Ceph vulnerabilities
Summary: Several security issues were fixed in Ceph.
Adam Mohammed discovered that Ceph incorrectly handled certain CORS
ExposeHeader tags. A remote attacker could possibly use this issue to
preform an HTTP header injection attack. (CVE-2020-10753)
Lei Cao discovered that Ceph incorrectly handled certain POST requests with
invalid tagging XML. A remote attacker could possibly use this issue to
cause Ceph to crash, leading to a denial of service. This issue only
affected Ubuntu 18.04 LTS. (CVE-2020-12059)
Robin H. Johnson discovered that Ceph incorrectly handled certain S3
requests. A remote attacker could possibly use this issue to perform a
XSS attack. (CVE-2020-1760)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ceph: header-splitting in RGW GetObject has a possible XSS
vendor_redhat·2020-04-06·CVSS 5.8
CVE-2020-1760 [MEDIUM] CWE-79 ceph: header-splitting in RGW GetObject has a possible XSS
ceph: header-splitting in RGW GetObject has a possible XSS
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
Statement: Red Hat OpenStack Platform 15 (RHOSP) packages Ceph but no longer uses it, instead pulling ceph directly from the Red Hat Ceph Storage 4 repository. For this reason, RHOSP will not be updated for this flaw.
This issue affects the versions of ceph as shipped with Red Hat Ceph Storage 3, 4 an
Debian
CVE-2020-1760: ceph - A flaw was found in the Ceph Object Gateway, where it supports request sent by a...
vendor_debian·2020·CVSS 5.8
CVE-2020-1760 [MEDIUM] CVE-2020-1760: ceph - A flaw was found in the Ceph Object Gateway, where it supports request sent by a...
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
Scope: local
bookworm: resolved (fixed in 14.2.9-1)
bullseye: resolved (fixed in 14.2.9-1)
forky: resolved (fixed in 14.2.9-1)
sid: resolved (fixed in 14.2.9-1)
trixie: resolved (fixed in 14.2.9-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-1760 ceph: header-splitting in RGW GetObject has a possible XSS [fedora-all]
bugzilla·2020-04-07·CVSS 5.8
CVE-2020-1760 [MEDIUM] CVE-2020-1760 ceph: header-splitting in RGW GetObject has a possible XSS [fedora-all]
CVE-2020-1760 ceph: header-splitting in RGW GetObject has a possible XSS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2020-1760 ceph: header-splitting in RGW GetObject has a possible XSS
bugzilla·2020-03-12·CVSS 5.8
CVE-2020-1760 [MEDIUM] CVE-2020-1760 ceph: header-splitting in RGW GetObject has a possible XSS
CVE-2020-1760 ceph: header-splitting in RGW GetObject has a possible XSS
If the attacker knows the path to a publicly readable object on any RGW cluster and the object is at least large enough to cover the attack body there it's possible to run an XSS on any object.
Discussion:
Mitigation:
* Mitigation provided by DigitalOcean:
Mitigation relies on the HAProxy load-balancers in front of RGW, and uses HAProxy ACLs combined with in-house Lua embedded in HAProxy.
1. Detect usage of the query-parameters without any signature (either pre-signed or header), and return S3-formatted error.
2. Validate the content in the query-parameters, return S3-formatted error.
HAProxy mitigation:
===
acl req_s3_GetObject REDACTED ## redacted uses internal Lua to detect GetObject
acl has_accesskey REDACT
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1760https://lists.debian.org/debian-lts-announce/2021/08/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P3A2UFR5IUIEXJUCF64GQ5OVLCZGODXE/https://security.gentoo.org/glsa/202105-39https://usn.ubuntu.com/4528-1/https://www.openwall.com/lists/oss-security/2020/04/07/1https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1760https://lists.debian.org/debian-lts-announce/2021/08/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P3A2UFR5IUIEXJUCF64GQ5OVLCZGODXE/https://security.gentoo.org/glsa/202105-39https://usn.ubuntu.com/4528-1/https://www.openwall.com/lists/oss-security/2020/04/07/1
2020-04-23
Published