Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cggp-94xr-prm6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.

EPSS

Процентиль: 61%
0.00407
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-113
CWE-74

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 5 лет назад

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.

CVSS3: 5.4
redhat
больше 5 лет назад

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.

CVSS3: 5.4
nvd
больше 5 лет назад

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.

CVSS3: 5.4
debian
больше 5 лет назад

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gate ...

suse-cvrf
больше 5 лет назад

Security update for ceph

EPSS

Процентиль: 61%
0.00407
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-113
CWE-74