Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

11 – 20 of 41 results


CVE-2021-3524

Medium priority

Some fixes available 10 of 12

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in...

1 affected packages

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ceph Fixed Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2021-20288

Medium priority

Some fixes available 5 of 8

An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can...

1 affected packages

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ceph Fixed Fixed Ignored Ignored
Show less packages

CVE-2020-25678

Low priority
Fixed

A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.

1 affected packages

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ceph Fixed Fixed Not affected Not affected
Show less packages

CVE-2020-27781

Medium priority

Some fixes available 10 of 12

User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx...

1 affected packages

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ceph Fixed Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2020-25660

Medium priority
Fixed

A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker...

1 affected packages

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ceph Fixed Not affected Not affected
Show less packages

CVE-2020-10753

Medium priority

Some fixes available 11 of 13

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the...

1 affected packages

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ceph Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2020-10736

Medium priority

Some fixes available 2 of 3

An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restrict access, resulting in gaining access to unauthorized resources. This flaw...

1 affected packages

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ceph Fixed Not affected Not affected
Show less packages

CVE-2020-1760

Medium priority

Some fixes available 2 of 4

A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.

1 affected packages

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ceph Not affected Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-12059

Medium priority
Fixed

An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.

1 affected packages

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ceph Not affected Fixed Not affected
Show less packages

CVE-2020-1699

Medium priority
Ignored

A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to...

1 affected packages

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
ceph Not affected Not affected
Show less packages