CVE-2021-3531
- EPSS 0.26%
- Veröffentlicht 18.05.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:21:46
A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a denial of service. The greatest threat to the system i...
CVE-2021-3524
- EPSS 0.54%
- Veröffentlicht 17.05.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:21:45
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the COR...
CVE-2021-20288
- EPSS 0.18%
- Veröffentlicht 15.04.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:46:17
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of ...
CVE-2020-25678
- EPSS 0.02%
- Veröffentlicht 08.01.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:26
A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.
CVE-2020-27781
- EPSS 0.04%
- Veröffentlicht 18.12.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:21:49
User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. ...
CVE-2020-25677
- EPSS 0.02%
- Veröffentlicht 08.12.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:26
A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerab...
CVE-2020-25660
- EPSS 0.27%
- Veröffentlicht 23.11.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:23
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the ...
CVE-2020-25626
- EPSS 0.84%
- Veröffentlicht 30.09.2020 20:15:15
- Zuletzt bearbeitet 21.11.2024 05:18:16
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control...
CVE-2020-14365
- EPSS 0.07%
- Veröffentlicht 23.09.2020 13:15:15
- Zuletzt bearbeitet 21.11.2024 05:03:06
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to ...
CVE-2020-10753
- EPSS 0.34%
- Veröffentlicht 26.06.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:59
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file genera...