A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s localStorage which is potentially vulnerable to attackers via XSS attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2021-05-26T21:25:44

Updated: 2024-08-04T16:25:43.403Z

Reserved: 2020-10-27T00:00:00

Link: CVE-2020-27839

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-05-26T22:15:07.863

Modified: 2021-06-03T18:37:46.990

Link: CVE-2020-27839

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-03-13T00:00:00Z

Links: CVE-2020-27839 - Bugzilla