vulnerability

CentOS Linux: CVE-2021-3524: Moderate: Red Hat Ceph Storage 5.1 Security, Enhancement, and Bug Fix update (Multiple Advisories)

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
2021-05-17
Added
2022-04-05
Modified
2023-05-25

Description

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. In addition, the prior bug fix for CVE-2020-10753 did not account for the use of \r as a header separator, thus a new flaw has been created.

Solution(s)

centos-upgrade-ceph-ansiblecentos-upgrade-ceph-basecentos-upgrade-ceph-base-debuginfocentos-upgrade-ceph-commoncentos-upgrade-ceph-common-debuginfocentos-upgrade-ceph-debuginfocentos-upgrade-ceph-debugsourcecentos-upgrade-ceph-fusecentos-upgrade-ceph-fuse-debuginfocentos-upgrade-ceph-grafana-dashboardscentos-upgrade-ceph-immutable-object-cachecentos-upgrade-ceph-immutable-object-cache-debuginfocentos-upgrade-ceph-iscsicentos-upgrade-ceph-mdscentos-upgrade-ceph-mds-debuginfocentos-upgrade-ceph-mgr-debuginfocentos-upgrade-ceph-mon-debuginfocentos-upgrade-ceph-osd-debuginfocentos-upgrade-ceph-radosgwcentos-upgrade-ceph-radosgw-debuginfocentos-upgrade-ceph-resource-agentscentos-upgrade-ceph-selinuxcentos-upgrade-ceph-test-debuginfocentos-upgrade-cephadmcentos-upgrade-cephadm-ansiblecentos-upgrade-cephfs-mirrorcentos-upgrade-cephfs-mirror-debuginfocentos-upgrade-cephfs-topcentos-upgrade-libcephfs-develcentos-upgrade-libcephfs2centos-upgrade-libcephfs2-debuginfocentos-upgrade-libcephsqlite-debuginfocentos-upgrade-libntirpccentos-upgrade-libntirpc-debuginfocentos-upgrade-libntirpc-debugsourcecentos-upgrade-librados-develcentos-upgrade-librados-devel-debuginfocentos-upgrade-libradospp-develcentos-upgrade-libradosstriper1centos-upgrade-libradosstriper1-debuginfocentos-upgrade-librbd-develcentos-upgrade-librgw-develcentos-upgrade-librgw2centos-upgrade-librgw2-debuginfocentos-upgrade-libtcmucentos-upgrade-nfs-ganeshacentos-upgrade-nfs-ganesha-cephcentos-upgrade-nfs-ganesha-ceph-debuginfocentos-upgrade-nfs-ganesha-debuginfocentos-upgrade-nfs-ganesha-debugsourcecentos-upgrade-nfs-ganesha-proxycentos-upgrade-nfs-ganesha-proxy-debuginfocentos-upgrade-nfs-ganesha-rados-gracecentos-upgrade-nfs-ganesha-rados-grace-debuginfocentos-upgrade-nfs-ganesha-rados-urlscentos-upgrade-nfs-ganesha-rados-urls-debuginfocentos-upgrade-nfs-ganesha-rgwcentos-upgrade-nfs-ganesha-rgw-debuginfocentos-upgrade-nfs-ganesha-selinuxcentos-upgrade-nfs-ganesha-vfscentos-upgrade-nfs-ganesha-vfs-debuginfocentos-upgrade-python-ceph-argparsecentos-upgrade-python-cephfscentos-upgrade-python-rgwcentos-upgrade-python3-ceph-argparsecentos-upgrade-python3-ceph-commoncentos-upgrade-python3-cephfscentos-upgrade-python3-cephfs-debuginfocentos-upgrade-python3-radoscentos-upgrade-python3-rados-debuginfocentos-upgrade-python3-rbdcentos-upgrade-python3-rbd-debuginfocentos-upgrade-python3-rgwcentos-upgrade-python3-rgw-debuginfocentos-upgrade-rbd-fuse-debuginfocentos-upgrade-rbd-mirrorcentos-upgrade-rbd-mirror-debuginfocentos-upgrade-rbd-nbdcentos-upgrade-rbd-nbd-debuginfocentos-upgrade-tcmu-runner
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.