rpm package
suse/ceph&distro=SUSE Linux Enterprise Software Development Kit 12 SP4
pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4
Vulnerabilities (6)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-10753 | — | < 12.2.13+git.1592168685.85110a3e9d-2.50.1 | 12.2.13+git.1592168685.85110a3e9d-2.50.1 | Jun 26, 2020 | A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the | ||
| CVE-2020-1760 | — | < 12.2.12+git.1585658687.363df3a813-2.42.4 | 12.2.12+git.1585658687.363df3a813-2.42.4 | Apr 23, 2020 | A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input. | ||
| CVE-2020-12059 | — | < 12.2.12+git.1587570958.35d78d0243-2.45.1 | 12.2.12+git.1587570958.35d78d0243-2.45.1 | Apr 22, 2020 | An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception. | ||
| CVE-2018-16889 | — | < 12.2.10+git.1549630712.bb089269ea-2.27.2 | 12.2.10+git.1549630712.bb089269ea-2.27.2 | Jan 28, 2019 | Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable. | ||
| CVE-2018-14662 | — | < 12.2.10+git.1549630712.bb089269ea-2.27.2 | 12.2.10+git.1549630712.bb089269ea-2.27.2 | Jan 15, 2019 | It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption. | ||
| CVE-2018-16846 | — | < 12.2.10+git.1549630712.bb089269ea-2.27.2 | 12.2.10+git.1549630712.bb089269ea-2.27.2 | Jan 15, 2019 | It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices. |
- CVE-2020-10753Jun 26, 2020affected < 12.2.13+git.1592168685.85110a3e9d-2.50.1fixed 12.2.13+git.1592168685.85110a3e9d-2.50.1
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the
- CVE-2020-1760Apr 23, 2020affected < 12.2.12+git.1585658687.363df3a813-2.42.4fixed 12.2.12+git.1585658687.363df3a813-2.42.4
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
- CVE-2020-12059Apr 22, 2020affected < 12.2.12+git.1587570958.35d78d0243-2.45.1fixed 12.2.12+git.1587570958.35d78d0243-2.45.1
An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.
- CVE-2018-16889Jan 28, 2019affected < 12.2.10+git.1549630712.bb089269ea-2.27.2fixed 12.2.10+git.1549630712.bb089269ea-2.27.2
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
- CVE-2018-14662Jan 15, 2019affected < 12.2.10+git.1549630712.bb089269ea-2.27.2fixed 12.2.10+git.1549630712.bb089269ea-2.27.2
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.
- CVE-2018-16846Jan 15, 2019affected < 12.2.10+git.1549630712.bb089269ea-2.27.2fixed 12.2.10+git.1549630712.bb089269ea-2.27.2
It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.