{"api_version":"1","generated_at":"2026-04-23T02:12:37+00:00","cve":"CVE-2020-27839","urls":{"html":"https://cve.report/CVE-2020-27839","api":"https://cve.report/api/cve/CVE-2020-27839.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-27839","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-27839"},"summary":{"title":"CVE-2020-27839","description":"A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s localStorage which is potentially vulnerable to attackers via XSS attacks. The highest threat from this vulnerability is to data confidentiality and integrity.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2021-05-26 22:15:00","updated_at":"2021-06-03 18:37:00"},"problem_types":["CWE-522"],"metrics":[],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1901330","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1901330","refsource":"MISC","tags":[],"title":"1901330 – (CVE-2020-27839) CVE-2020-27839 ceph-dashboard: Don't use Browser's LocalStorage for storing JWT but Secure Cookies with proper HTTP Headers","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-27839","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-27839","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"27839","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"ceph","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-27839","qid":"174881","title":"SUSE Enterprise Linux Security Update for ceph (SUSE-SU-2021:1108-1)"},{"cve":"CVE-2020-27839","qid":"174975","title":"SUSE Enterprise Linux Security Update for ceph (SUSE-SU-2021:1473-1)"},{"cve":"CVE-2020-27839","qid":"198423","title":"Ubuntu Security Notification for Ceph vulnerabilities (USN-4998-1)"},{"cve":"CVE-2020-27839","qid":"239428","title":"Red Hat Update for Red Hat Ceph Storage 4.2 (RHSA-2021:2445)"},{"cve":"CVE-2020-27839","qid":"281589","title":"Fedora Security Update for ceph (FEDORA-2021-93ff9e9103)"},{"cve":"CVE-2020-27839","qid":"750271","title":"OpenSUSE Security Update for ceph (openSUSE-SU-2021:0544-1)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-27839","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"ceph-dashboard","version":{"version_data":[{"version_value":"ceph-dashboard 14.2.17, ceph-dashboard 15.2.9"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-522"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1901330","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1901330"}]},"description":{"description_data":[{"lang":"eng","value":"A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s localStorage which is potentially vulnerable to attackers via XSS attacks. The highest threat from this vulnerability is to data confidentiality and integrity."}]}},"nvd":{"publishedDate":"2021-05-26 22:15:00","lastModifiedDate":"2021-06-03 18:37:00","problem_types":["CWE-522"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:ceph:*:*:*:*:*:*:*:*","versionEndExcluding":"14.2.17","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:ceph:*:*:*:*:*:*:*:*","versionStartIncluding":"15.2.0","versionEndExcluding":"15.2.9","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"27839","Ordinal":"189575","Title":"CVE-2020-27839","CVE":"CVE-2020-27839","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"27839","Ordinal":"1","NoteData":"A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s localStorage which is potentially vulnerable to attackers via XSS attacks. The highest threat from this vulnerability is to data confidentiality and integrity.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"27839","Ordinal":"2","NoteData":"2021-05-26","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"27839","Ordinal":"3","NoteData":"2021-05-26","Type":"Other","Title":"Modified"}]}}}