Improper Neutralization of Special Elements in Output Used by a Downstream Component in Ceph - CVE-2020-10753

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Ceph - CVE-2020-10753

Published: June 26, 2020 / Updated: November 24, 2020


Vulnerability identifier: #VU48628
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10753
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.


Affected software

Ceph
Arch Linux
Gentoo Linux
openEuler
Ubuntu
Fedora
ceph (Alpine package)
ceph-medic (Red Hat package)
cockpit-ceph-installer (Red Hat package)
nfs-ganesha (Red Hat package)
ceph-ansible (Red Hat package)
rbd-mirror
python3-ceph-argparse
rbd-fuse
libcephfs2
ceph-selinux
librados-devel
librgw2
python-rbd
python3-rados
libradosstriper1
python3-rbd
ceph-debuginfo
librbd1
rbd-nbd
python-ceph-compat
librados2
ceph-radosgw
ceph-debugsource
python-cephfs
ceph-mon
ceph-common
librgw-devel
ceph-mds
ceph-osd
libcephfs-devel
ceph
ceph-fuse
rados-objclass-devel
python-rados
ceph-test
ceph-base
python3-cephfs
python3-rgw
librbd-devel
libradosstriper-devel
ceph-resource-agents
python-rgw
ceph-mgr
ceph (Red Hat package)
ceph-common (Ubuntu package)
ceph-base (Ubuntu package)
ceph (Ubuntu package)
Red Hat Ceph Storage

How to mitigate CVE-2020-10753

Install update from vendor's website.

ceph-medic (Red Hat package) - addressed in versions 1.0.8-1.el7cp, 1.0.8-1.el8cp
cockpit-ceph-installer (Red Hat package) - addressed in versions 1.2-0.el7cp, 1.2-0.el8cp
nfs-ganesha (Red Hat package) - addressed in versions 2.7.4-13.el7cp, 2.8.3-8.el7cp, 2.8.3-8.el8cp
ceph-ansible (Red Hat package) - addressed in versions 3.2.48-1.el7cp, 4.0.25-1.el7cp, 4.0.25-1.el8cp
Red Hat Ceph Storage - addressed in versions 3.3, 4.1
rbd-mirror - update to 12.2.8-15
python3-ceph-argparse - update to 12.2.8-15
rbd-fuse - update to 12.2.8-15
libcephfs2 - update to 12.2.8-15
ceph-selinux - update to 12.2.8-15
librados-devel - update to 12.2.8-15
librgw2 - update to 12.2.8-15
python-rbd - update to 12.2.8-15
python3-rados - update to 12.2.8-15
libradosstriper1 - update to 12.2.8-15
python3-rbd - update to 12.2.8-15
ceph-debuginfo - update to 12.2.8-15
librbd1 - update to 12.2.8-15
rbd-nbd - update to 12.2.8-15
python-ceph-compat - update to 12.2.8-15
librados2 - update to 12.2.8-15
ceph-radosgw - update to 12.2.8-15
ceph-debugsource - update to 12.2.8-15
python-cephfs - update to 12.2.8-15
ceph-mon - update to 12.2.8-15
ceph-common - update to 12.2.8-15
librgw-devel - update to 12.2.8-15
ceph-mds - update to 12.2.8-15
ceph-osd - update to 12.2.8-15
libcephfs-devel - update to 12.2.8-15
ceph - update to 12.2.8-15
ceph-fuse - update to 12.2.8-15
rados-objclass-devel - update to 12.2.8-15
python-rados - update to 12.2.8-15
ceph-test - update to 12.2.8-15
ceph-base - update to 12.2.8-15
python3-cephfs - update to 12.2.8-15
python3-rgw - update to 12.2.8-15
librbd-devel - update to 12.2.8-15
libradosstriper-devel - update to 12.2.8-15
ceph-resource-agents - update to 12.2.8-15
python-rgw - update to 12.2.8-15
ceph-mgr - update to 12.2.8-15
ceph (Red Hat package) - addressed in versions 12.2.12-124.el7cp, 14.2.8-81.el7cp, 14.2.8-81.el8cp
ceph - update to 14.2.10-1.fc32
ceph-common (Ubuntu package) - addressed in versions 15.2.7-0ubuntu0.20.04.2, 15.2.7-0ubuntu0.20.10.3
ceph-base (Ubuntu package) - addressed in versions 15.2.7-0ubuntu0.20.04.2, 15.2.7-0ubuntu0.20.10.3
ceph (Ubuntu package) - addressed in versions 15.2.7-0ubuntu0.20.04.2, 15.2.7-0ubuntu0.20.10.3

External References

Related Security Bulletins