Description
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2735-1 | ceph security update |
Debian DLA |
DLA-3629-1 | ceph security update |
EUVD |
EUVD-2020-3171 | A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue. |
Ubuntu USN |
USN-4528-1 | Ceph vulnerabilities |
Ubuntu USN |
USN-4706-1 | Ceph vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T11:14:15.190Z
Reserved: 2020-03-20T00:00:00.000Z
Link: CVE-2020-10753
No data.
Status : Modified
Published: 2020-06-26T15:15:11.573
Modified: 2024-11-21T04:55:59.890
Link: CVE-2020-10753
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN