CVE-2020-1760
Summary
| CVE | CVE-2020-1760 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-23 15:15:00 UTC |
| Updated | 2023-11-07 03:19:00 UTC |
| Description | A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| oss-security - CVE-2020-1760 ceph: header-splitting in RGW GetObject has a possible XSS |
MISC |
www.openwall.com |
Mailing List, Patch, Third Party Advisory |
| [SECURITY] [DLA 3629-1] ceph security update |
MLIST |
lists.debian.org |
|
| USN-4528-1: Ceph vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| [SECURITY] [DLA 2735-1] ceph security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 31 Update: ceph-14.2.9-1.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: ceph-14.2.9-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Ceph: Multiple vulnerabilities (GLSA 202105-39) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| 1812962 – (CVE-2020-1760) CVE-2020-1760 ceph: header-splitting in RGW GetObject has a possible XSS |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178752 Debian Security Update for ceph (DLA 2735-1)
- 500847 Alpine Linux Security Update for ceph
- 502824 Alpine Linux Security Update for ceph16
- 6000278 Debian Security Update for ceph (DLA 3629-1)
- 670565 EulerOS Security Update for ceph-common (EulerOS-SA-2021-2322)
- 671233 EulerOS Security Update for ceph-common (EulerOS-SA-2022-1157)
- 671605 EulerOS Security Update for ceph (EulerOS-SA-2022-1558)
- 710075 Gentoo Linux Ceph Multiple vulnerabilities (GLSA 202105-39)