5.4
CVSSv3

CVE-2020-27839

Published: 26/05/2021 Updated: 03/06/2021
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A security issue was found in ceph in versions before 15.2.9. The JWT token used by the ceph dashboard for authorising against the API was stored inside the local storage of the browser, making it vulnerable to cross-site scripting attacks. Ceph version 15.2.9 mitigates this issue by using secure cookies for storage instead.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ceph

Vendor Advisories

Debian Bug report logs - #985670 CVE-2020-27781 CVE-2020-27839 Package: ceph; Maintainer for ceph is Ceph Packaging Team <team+ceph@trackerdebianorg>; Source for ceph is src:ceph (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 21 Mar 2021 19:03:00 UTC Severity: important Tags: sec ...
A security issue was found in ceph in versions prior to 1529 The JWT token used by the ceph dashboard for authorising against the API was stored inside the local storage of the browser, making it vulnerable to cross-site scripting attacks Ceph version 1529 mitigates this issue by using secure cookies for storage instead ...