For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
Red Hat Ceph Storage is a scalable, open, software-defined storage platform
that combines the most stable version of the Ceph storage system with a
Ceph management platform, deployment utilities, and support services.
Security Fix(es):
* ceph: header-splitting in RGW GetObject has a possible XSS
(CVE-2020-1760)
* ceph: radosgw: HTTP header injection via CORS ExposeHeader tag
(CVE-2020-10753)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
For detailed information on changes in this release, see the Red Hat Ceph
Storage 4.1 Release Notes available at:
/release_notes/
https://access.redhat.com/security/cve/CVE-2020-1760 https://access.redhat.com/security/cve/CVE-2020-10753 https://access.redhat.com/security/updates/classification#moderate
Red Hat Ceph Storage 4.0 MON:
Source:
ceph-14.2.8-81.el7cp.src.rpm
noarch:
ceph-grafana-dashboards-14.2.8-81.el7cp.noarch.rpm
ceph-mgr-dashboard-14.2.8-81.el7cp.noarch.rpm
ceph-mgr-diskprediction-local-14.2.8-81.el7cp.noarch.rpm
ceph-mgr-k8sevents-14.2.8-81.el7cp.noarch.rpm
ceph-mgr-rook-14.2.8-81.el7cp.noarch.rpm
ppc64le:
ceph-base-14.2.8-81.el7cp.ppc64le.rpm
ceph-common-14.2.8-81.el7cp.ppc64le.rpm
ceph-debuginfo-14.2.8-81.el7cp.ppc64le.rpm
ceph-mgr-14.2.8-81.el7cp.ppc64le.rpm
ceph-mon-14.2.8-81.el7cp.ppc64le.rpm
ceph-selinux-14.2.8-81.el7cp.ppc64le.rpm
ceph-test-14.2.8-81.el7cp.ppc64le.rpm
libcephfs-devel-14.2.8-81.el7cp.ppc64le.rpm
libcephfs2-14.2.8-81.el7cp.ppc64le.rpm
librados-devel-14.2.8-81.el7cp.ppc64le.rpm
librados2-14.2.8-81.el7cp.ppc64le.rpm
libradospp-devel-14.2.8-81.el7cp.ppc64le.rpm
libradosstriper1-14.2.8-81.el7cp.ppc64le.rpm
librbd-devel-14.2.8-81.el7cp.ppc64le.rpm
librbd1-14.2.8-81.el7cp.ppc64le.rpm
librgw-devel-14.2.8-81.el7cp.ppc64le.rpm
librgw2-14.2.8-81.el7cp.ppc64le.rpm
python-ceph-argparse-14.2.8-81.el7cp.ppc64le.rpm
python-cephfs-14.2.8-81.el7cp.ppc64le.rpm
python-rados-14.2.8-81.el7cp.ppc64le.rpm
python-rbd-14.2.8-81.el7cp.ppc64le.rpm
python-rgw-14.2.8-81.el7cp.ppc64le.rpm
x86_64:
ceph-base-14.2.8-81.el7cp.x86_64.rpm
Read the Full Advisory
An update is now available for Red Hat Ceph Storage 4.1.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Red Hat Ceph Storage 4.0 MON - noarch, ppc64le, x86_64
Red Hat Ceph Storage 4.1 MON - noarch, ppc64le, s390x, x86_64
Red Hat Ceph Storage 4.1 OSD - ppc64le, s390x, x86_64
Red Hat Ceph Storage 4.1 Tools - noarch, ppc64le, s390x, x86_64
1756077 - Fix compile of ceph on s390x
1785445 - mgr/k8sevents does not account for incomplete events passed in from kubernetes
1791143 - [RFE] [cockpit-ceph-installer] if using customer created user with passwordless sudo check if they also created ssh-keys and use them instead of ansible-runner-service keys
1797774 - update default crush_rule conditional check
1800644 - RFE add ability to set dashboard password in Cockpit installer
1800664 - FileStore messaging should say it is deprecated
1809003 - [GSS] Starting of service 'ansible-runner-service' fails with error during deployment of Ceph cluster,
1809870 - [GSS] cockpit-installer doesn't allows to change the configuration if the Installation fails.
1810949 - PG premerge stall
1812962 - CVE-2020-1760 ceph: header-splitting in RGW GetObject has a possible XSS
1814177 - [GSS] Ansible inventory file is not getting populated after the Ceph cluster deployment using Cockpit
1816478 - The installer's probe mechanism fails on more complex network configurations.
1819667 - some "ceph mds" sub commands returns error message "no valid command found"
1826002 - Refresh ceph dashboard user role
1827607 - tasks/create_mds_filesystems: don't enable application 'cephfs' on the filesystem's pools
1828232 - SELinux denials observed against ceph-mgr
Get the latest Linux and open source security news straight to your inbox.