Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE Enterprise Storage 6: 2021:1472-1 Critical Ceph and Deepsea Fixes

suse
Calendar Grey May 4, 2021
Scroller Suse
Tackling essential updates for ceph and deepsea, specifically targeting vulnerabilities linked to the access of sensitive data and problems with user authorization.
An update that solves three vulnerabilities and has 16 fixes is now available

Summary

This update for ceph, deepsea fixes the following issues: - ceph was updated to 14.2.20-402-g6aa76c6815: * CVE-2021-20288: Fixed unauthorized global_id reuse (bsc#1183074). * CVE-2020-25678: Do not add sensitive information in Ceph log files (bsc#1178905). * CVE-2020-27839: Use secure cookies to store JWT Token (bsc#1179997). * mgr/dashboard: prometheus alerting: add some leeway for package drops and errors (bsc#1145463) * mon: have 'mon stat' output json as well (bsc#1174466) * rpm: ceph-mgr-dashboard recommends python3-saml on SUSE (bsc#1177200) * mgr/dashboard: Display a warning message in Dashboard when debug mode is enabled (bsc#1178235) * rgw: cls/user: set from_index for reset stats calls (bsc#1178837) * mgr/dashboard: Disable TLS 1.0 and 1.1 (bsc#1178860)

References

#1145463 #1174466 #1177200 #1178016 #1178216

#1178235 #1178657 #1178837 #1178860 #1178905

#1179997 #1180118 #1180594 #1181183 #1181378

#1181665 #1183074 #1183487 #1183600

Cross- CVE-2020-25678 CVE-2020-27839 CVE-2021-20288

CVSS scores:

CVE-2020-25678 (NVD) : 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CVE-2020-27839 (SUSE): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVE-2021-20288 (NVD) : 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVE-2021-20288 (SUSE): 8 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Affected Products:

SUSE Enterprise Storage 6

https://www.suse.com/security/cve/CVE-2020-25678.html

https://www.suse.com/security/cve/CVE-2020-27839.html

https://www.suse.com/security/cve/CVE-2021-20288.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:1472-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.