VDB
CNVD-2020-32852
CNVD-2020-32852
PUBLISHED
CVSS 5.800000190734863 MEDIUM
Red Hat Ceph是美国红帽(Red Hat)公司的一套Linux PB级分布式文件系统。该系统的主要目标是设计成基于POSIX(可移植操作系统接口)的没有单点故障的分布式文件系统,使数据能容错和无缝的复制。 Red Hat Ceph Object Gateway中存在跨站脚本漏洞。该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
Risk Scores
CVSS 3.1
5.800000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| [UNKNOWN] | ceph | 15.2.1, 13.2.9, 14.2.9 |
Exploit Intelligence
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1760 (circl)
- https://www.openwall.com/lists/oss-security/2020/04/07/1 (circl)
- FEDORA-2020-81b9c6cddc (circl)
- USN-4528-1 (circl)
- GLSA-202105-39 (circl)
- [debian-lts-announce] 20210810 [SECURITY] [DLA 2735-1] ceph security update (circl)
- [debian-lts-announce] 20231023 [SECURITY] [DLA 3629-1] ceph security update (circl)
Timeline
- Apr 6, 2020 CVE Published
- Apr 1, 2026 Security Advisory
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1760 url
- https://www.openwall.com/lists/oss-security/2020/04/07/1 url
- FEDORA-2020-81b9c6cddc vendor-advisory
- USN-4528-1 vendor-advisory
- GLSA-202105-39 vendor-advisory
- [debian-lts-announce] 20210810 [SECURITY] [DLA 2735-1] ceph security update mailing-list
- [debian-lts-announce] 20231023 [SECURITY] [DLA 3629-1] ceph security update mailing-list