vulnerability

Red Hat: CVE-2021-3524: Moderate: Red Hat Ceph Storage 5.1 Security, Enhancement, and Bug Fix update (Multiple Advisories)

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
2021-05-17
Added
2022-04-05
Modified
2022-05-06

Description

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. In addition, the prior bug fix for CVE-2020-10753 did not account for the use of \r as a header separator, thus a new flaw has been created.

Solution(s)

redhat-upgrade-ceph-ansibleredhat-upgrade-ceph-baseredhat-upgrade-ceph-base-debuginforedhat-upgrade-ceph-commonredhat-upgrade-ceph-common-debuginforedhat-upgrade-ceph-debuginforedhat-upgrade-ceph-debugsourceredhat-upgrade-ceph-fuseredhat-upgrade-ceph-fuse-debuginforedhat-upgrade-ceph-grafana-dashboardsredhat-upgrade-ceph-immutable-object-cacheredhat-upgrade-ceph-immutable-object-cache-debuginforedhat-upgrade-ceph-iscsiredhat-upgrade-ceph-mdsredhat-upgrade-ceph-mds-debuginforedhat-upgrade-ceph-mgr-debuginforedhat-upgrade-ceph-mon-debuginforedhat-upgrade-ceph-osd-debuginforedhat-upgrade-ceph-radosgwredhat-upgrade-ceph-radosgw-debuginforedhat-upgrade-ceph-resource-agentsredhat-upgrade-ceph-selinuxredhat-upgrade-ceph-test-debuginforedhat-upgrade-cephadmredhat-upgrade-cephadm-ansibleredhat-upgrade-cephfs-mirrorredhat-upgrade-cephfs-mirror-debuginforedhat-upgrade-cephfs-topredhat-upgrade-libcephfs-develredhat-upgrade-libcephfs2redhat-upgrade-libcephfs2-debuginforedhat-upgrade-libcephsqlite-debuginforedhat-upgrade-libntirpcredhat-upgrade-libntirpc-debuginforedhat-upgrade-libntirpc-debugsourceredhat-upgrade-librados-develredhat-upgrade-librados-devel-debuginforedhat-upgrade-libradospp-develredhat-upgrade-libradosstriper1redhat-upgrade-libradosstriper1-debuginforedhat-upgrade-librbd-develredhat-upgrade-librgw-develredhat-upgrade-librgw2redhat-upgrade-librgw2-debuginforedhat-upgrade-libtcmuredhat-upgrade-nfs-ganesharedhat-upgrade-nfs-ganesha-cephredhat-upgrade-nfs-ganesha-ceph-debuginforedhat-upgrade-nfs-ganesha-debuginforedhat-upgrade-nfs-ganesha-debugsourceredhat-upgrade-nfs-ganesha-proxyredhat-upgrade-nfs-ganesha-proxy-debuginforedhat-upgrade-nfs-ganesha-rados-graceredhat-upgrade-nfs-ganesha-rados-grace-debuginforedhat-upgrade-nfs-ganesha-rados-urlsredhat-upgrade-nfs-ganesha-rados-urls-debuginforedhat-upgrade-nfs-ganesha-rgwredhat-upgrade-nfs-ganesha-rgw-debuginforedhat-upgrade-nfs-ganesha-selinuxredhat-upgrade-nfs-ganesha-vfsredhat-upgrade-nfs-ganesha-vfs-debuginforedhat-upgrade-python-ceph-argparseredhat-upgrade-python-cephfsredhat-upgrade-python-rgwredhat-upgrade-python3-ceph-argparseredhat-upgrade-python3-ceph-commonredhat-upgrade-python3-cephfsredhat-upgrade-python3-cephfs-debuginforedhat-upgrade-python3-radosredhat-upgrade-python3-rados-debuginforedhat-upgrade-python3-rbdredhat-upgrade-python3-rbd-debuginforedhat-upgrade-python3-rgwredhat-upgrade-python3-rgw-debuginforedhat-upgrade-rbd-fuse-debuginforedhat-upgrade-rbd-mirrorredhat-upgrade-rbd-mirror-debuginforedhat-upgrade-rbd-nbdredhat-upgrade-rbd-nbd-debuginforedhat-upgrade-tcmu-runner
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.