RedHat: RHSA-2020-3505:01 Moderate: Red Hat Ceph Storage 3.3 Security update
Summary
Red Hat Ceph Storage is a scalable, open, software-defined storage platform
that combines the most stable version of the Ceph storage system with a
Ceph management platform, deployment utilities, and support services.
Security Fix(es):
* ceph: radosgw: HTTP header injection via CORS ExposeHeader tag
(CVE-2020-10753)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Summary
Solution
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
ingle/installation_guide_for_ubuntu/index#upgrading-the-storage-cluster
References
https://access.redhat.com/security/cve/CVE-2020-10753 https://access.redhat.com/security/updates/classification/#moderate
Package List
Topic
An update is now available for Red Hat Ceph Storage 3.3 on Ubuntu16.04.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Topic
Relevant Releases Architectures
Bugs Fixed
1840744 - CVE-2020-10753 ceph: radosgw: HTTP header injection via CORS ExposeHeader tag