cbcvebase.
CVE-2021-3524
published 2021-05-17

CVE-2021-3524: A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP…

PriorityP433medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
1.61%
73.2th percentile
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. In addition, the prior bug fix for CVE-2020-10753 did not account for the use of \r as a header separator, thus a new flaw has been created.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianceph< ceph 14.2.21-1 (bookworm)ceph 14.2.21-1 (bookworm)
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
redhatceph< 14.2.2114.2.21
redhatceph>= 0 < 14.2.21-114.2.21-1
redhatceph>= 0 < 14.2.21-114.2.21-1
redhatceph>= 0 < 14.2.21-114.2.21-1
redhatceph>= 0 < 14.2.21-114.2.21-1
redhatceph>= 0 < 12.2.13-0ubuntu0.18.04.1012.2.13-0ubuntu0.18.04.10
redhatceph>= 0 < 15.2.12-0ubuntu0.20.04.115.2.12-0ubuntu0.20.04.1
redhatceph>= 0 < 0.80.11-0ubuntu1.14.04.4+esm30.80.11-0ubuntu1.14.04.4+esm3
redhatceph>= 0 < 10.2.11-0ubuntu0.16.04.3+esm210.2.11-0ubuntu0.16.04.3+esm2
redhatceph_storage

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv7.1HIGH
vendor_ubuntu7.1HIGH
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.