Stored cross-site scripting in ceph-ci - CVE-2020-1760

 

Stored cross-site scripting in ceph-ci - CVE-2020-1760

Published: July 26, 2020 / Updated: August 24, 2020


Vulnerability identifier: #VU31882
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2020-1760
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. A remote attacker can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

ceph-ci
Gentoo Linux
Arch Linux
Opensuse
openEuler
Fedora
Ceph
ceph (Alpine package)
ceph-medic (Red Hat package)
cockpit-ceph-installer (Red Hat package)
nfs-ganesha (Red Hat package)
ceph-ansible (Red Hat package)
rbd-mirror
ceph-selinux
libcephfs2
rbd-fuse
python3-ceph-argparse
librados-devel
librgw2
python-rbd
python3-rados
libradosstriper1
python3-rbd
librbd-devel
librbd1
rbd-nbd
python-ceph-compat
librados2
ceph-radosgw
ceph-debugsource
python-cephfs
ceph-mon
ceph-common
librgw-devel
ceph-mds
ceph-osd
libcephfs-devel
ceph
ceph-fuse
rados-objclass-devel
python-rados
ceph-test
ceph-base
python3-cephfs
ceph-debuginfo
python3-rgw
libradosstriper-devel
ceph-resource-agents
python-rgw
ceph-mgr
ceph (Red Hat package)
Red Hat Ceph Storage

How to mitigate CVE-2020-1760

Install updates from vendor's website.

ceph-ci - addressed in versions 13.2.9, 14.2.9, 15.2.1
Ceph - addressed in versions 13.2.9, 14.2.9, 15.1.1, 15.2.1
ceph (Alpine package) - update to 14.2.9-r0
ceph-medic (Red Hat package) - addressed in versions 1.0.8-1.el7cp, 1.0.8-1.el8cp
cockpit-ceph-installer (Red Hat package) - addressed in versions 1.2-0.el7cp, 1.2-0.el8cp
nfs-ganesha (Red Hat package) - addressed in versions 2.8.3-8.el7cp, 2.8.3-8.el8cp
ceph-ansible (Red Hat package) - addressed in versions 4.0.25-1.el7cp, 4.0.25-1.el8cp
Red Hat Ceph Storage - update to 4.1
rbd-mirror - update to 12.2.8-15
ceph-selinux - update to 12.2.8-15
libcephfs2 - update to 12.2.8-15
rbd-fuse - update to 12.2.8-15
python3-ceph-argparse - update to 12.2.8-15
librados-devel - update to 12.2.8-15
librgw2 - update to 12.2.8-15
python-rbd - update to 12.2.8-15
python3-rados - update to 12.2.8-15
libradosstriper1 - update to 12.2.8-15
python3-rbd - update to 12.2.8-15
librbd-devel - update to 12.2.8-15
librbd1 - update to 12.2.8-15
rbd-nbd - update to 12.2.8-15
python-ceph-compat - update to 12.2.8-15
librados2 - update to 12.2.8-15
ceph-radosgw - update to 12.2.8-15
ceph-debugsource - update to 12.2.8-15
python-cephfs - update to 12.2.8-15
ceph-mon - update to 12.2.8-15
ceph-common - update to 12.2.8-15
librgw-devel - update to 12.2.8-15
ceph-mds - update to 12.2.8-15
ceph-osd - update to 12.2.8-15
libcephfs-devel - update to 12.2.8-15
ceph - update to 12.2.8-15
ceph-fuse - update to 12.2.8-15
rados-objclass-devel - update to 12.2.8-15
python-rados - update to 12.2.8-15
ceph-test - update to 12.2.8-15
ceph-base - update to 12.2.8-15
python3-cephfs - update to 12.2.8-15
ceph-debuginfo - update to 12.2.8-15
python3-rgw - update to 12.2.8-15
libradosstriper-devel - update to 12.2.8-15
ceph-resource-agents - update to 12.2.8-15
python-rgw - update to 12.2.8-15
ceph-mgr - update to 12.2.8-15
ceph (Red Hat package) - addressed in versions 14.2.8-81.el7cp, 14.2.8-81.el8cp
ceph - update to 14.2.9-1.fc31

External References

Related Security Bulletins