A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2171-1 | ceph security update |
Debian DLA |
DLA-2735-1 | ceph security update |
Debian DLA |
DLA-3629-1 | ceph security update |
EUVD |
EUVD-2020-12588 | A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input. |
Ubuntu USN |
USN-4528-1 | Ceph vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T06:46:30.894Z
Reserved: 2019-11-27T00:00:00
Link: CVE-2020-1760
No data.
Status : Modified
Published: 2020-04-23T15:15:14.607
Modified: 2024-11-21T05:11:19.730
Link: CVE-2020-1760
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN