A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
redhat ceph storage 3.0 |
||
redhat ceph storage 4.0 |
||
redhat openstack 15 |
||
fedoraproject fedora 32 |
||
opensuse leap 15.1 |
||
linuxfoundation ceph |
||
canonical ubuntu linux 18.04 |
||
canonical ubuntu linux 16.04 |