VYPR

rpm package

suse/ceph&distro=SUSE Linux Enterprise Software Development Kit 12 SP5

pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5

Vulnerabilities (3)

  • CVE-2020-10753Jun 26, 2020
    affected < 12.2.13+git.1592168685.85110a3e9d-2.50.1fixed 12.2.13+git.1592168685.85110a3e9d-2.50.1

    A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the

  • CVE-2020-1760Apr 23, 2020
    affected < 12.2.12+git.1585658687.363df3a813-2.42.4fixed 12.2.12+git.1585658687.363df3a813-2.42.4

    A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.

  • CVE-2020-12059Apr 22, 2020
    affected < 12.2.12+git.1587570958.35d78d0243-2.45.1fixed 12.2.12+git.1587570958.35d78d0243-2.45.1

    An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.