-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: Red Hat Ceph Storage 3.3 Security update
Advisory ID:       RHSA-2020:3505-01
Product:           Red Hat Ceph Storage
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:3505
Issue date:        2020-08-18
CVE Names:         CVE-2020-10753 
====================================================================
1. Summary:

An update is now available for Red Hat Ceph Storage 3.3 on Ubuntu
16.04.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Red Hat Ceph Storage is a scalable, open, software-defined storage platform
that combines the most stable version of the Ceph storage system with a
Ceph management platform, deployment utilities, and support services.

Security Fix(es):

* ceph: radosgw: HTTP header injection via CORS ExposeHeader tag
(CVE-2020-10753)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

ingle/installation_guide_for_ubuntu/index#upgrading-the-storage-cluster

4. Bugs fixed (https://bugzilla.redhat.com/):

1840744 - CVE-2020-10753 ceph: radosgw: HTTP header injection via CORS ExposeHeader tag

5. References:

https://access.redhat.com/security/cve/CVE-2020-10753
https://access.redhat.com/security/updates/classification/#moderate

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXzwX5tzjgjWX9erEAQhX2w/+J9Jb4Z2cCY/2IyP6rWorLXtCu/GcJzT7
bpRJU6UB3sQeLIxoEYvIDasnz3DGbXET1X8XOwygBC8sSeIMd3WFwN1A/NUyhVZ/
NASRuKbyFmSD9vR+asVxQ5rsDbMW1e/EhrbTDSGQzZqqvQUgQEMKiNstn+Rvq4rc
jAT4oyni8xV9ujLQekaVJMCD4FYTp7OALmgkdioGEoB72HrJ7oXf5NnNOuLS9ysq
4QN8qrnfiyHRfr0dosdFl6W7Hl7GeFMGks+79AA82QfdBjKdxnmq7MgqSfD3+WGS
aBeJ+pyq4IS0QV9Z5oDR+E7EOOMv67teT4pUWeCMZ+//Hj6NI4/7/Ko5Qzu73xKl
dfCnD9uWdYG2ILXPNOQyxvui+lEGLihajvov6zUP+inCVsD6c+jljtAKzVgQsR4H
ZIzlHcdBffFHOc0E1noWy9Ew1jp3n7sUXdhEo2sOSk5ZzEbUT+21UALHiUjw1i6b
xZfv7sDHbzcuOKaT9EKV6yhBHTtnhu2FbbjR04tHGCtjcFNxU3PfBMa4Z/ALZePK
q1S6sM2QxDd2afAmYBuyAKdWEKRSeV71SE9agLGbXawnyoJKW6xxznF7fRC2i/RR
YcwdxD8oQr+pDIBo3K50BQkp3GhsFDf/XoFg0iK7Hk34p1aBKiHXMU7p+MNbdCMo
cMpG4+gcHrE=K+/0
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2020-3505:01 Moderate: Red Hat Ceph Storage 3.3 Security update

An update is now available for Red Hat Ceph Storage 3.3 on Ubuntu 16.04

Summary

Red Hat Ceph Storage is a scalable, open, software-defined storage platform that combines the most stable version of the Ceph storage system with a Ceph management platform, deployment utilities, and support services.
Security Fix(es):
* ceph: radosgw: HTTP header injection via CORS ExposeHeader tag (CVE-2020-10753)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
ingle/installation_guide_for_ubuntu/index#upgrading-the-storage-cluster

References

https://access.redhat.com/security/cve/CVE-2020-10753 https://access.redhat.com/security/updates/classification/#moderate

Package List


Severity
Advisory ID: RHSA-2020:3505-01
Product: Red Hat Ceph Storage
Advisory URL: https://access.redhat.com/errata/RHSA-2020:3505
Issued Date: : 2020-08-18
CVE Names: CVE-2020-10753

Topic

An update is now available for Red Hat Ceph Storage 3.3 on Ubuntu16.04.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

1840744 - CVE-2020-10753 ceph: radosgw: HTTP header injection via CORS ExposeHeader tag


Related News