CVE-2020-1760

MEDIUM

Ceph < 14.2.21 - Cross-Site Scripting via Anonymous S3 Request Handling

Title source: llm
STIX 2.1

Description

A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.

References (7)

Core 7
Core References
Third Party Advisory vendor-advisory
https://usn.ubuntu.com/4528-1/
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202105-39
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2021/08/msg00013.html
Issue Tracking, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1760
Mailing List, Patch, Third Party Advisory
https://www.openwall.com/lists/oss-security/2020/04/07/1

Scores

CVSS v3 5.8
EPSS 0.0035
EPSS Percentile 57.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L

Details

CWE
CWE-79
Status published
Products (8)
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
debian/debian_linux 9.0
fedoraproject/fedora 31
linuxfoundation/ceph < 14.2.21
redhat/ceph_storage 3.0
redhat/ceph_storage 4.0
redhat/openshift_container_platform 4.2
Published Apr 23, 2020
Tracked Since Feb 18, 2026