Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-1699

Опубликовано: 21 апр. 2020
Источник: debian
EPSS Низкий

Описание

A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to cause information disclosure on the host machine running the Ceph dashboard.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cephfixed14.2.6-4package
cephnot-affectedbusterpackage
cephnot-affectedstretchpackage
cephnot-affectedjessiepackage

Примечания

  • https://tracker.ceph.com/issues/41320

  • https://github.com/ceph/ceph/commit/0443e40c11280ba3b7efcba61522afa70c4f8158

EPSS

Процентиль: 83%
0.01822
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to cause information disclosure on the host machine running the Ceph dashboard.

CVSS3: 7.5
redhat
около 6 лет назад

A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to cause information disclosure on the host machine running the Ceph dashboard.

CVSS3: 7.5
nvd
почти 6 лет назад

A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to cause information disclosure on the host machine running the Ceph dashboard.

github
больше 3 лет назад

A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to cause information disclosure on the host machine running the Ceph dashboard.

suse-cvrf
почти 6 лет назад

Security update for ceph

EPSS

Процентиль: 83%
0.01822
Низкий