RHSA-2021:1518HighCVSS 8.2
Red Hat Security Advisory: Red Hat Ceph Storage 3.3 Security and Bug Fix Update
🔗 CVE IDs covered (4)
📋 Description
CVE-2020-12059 — ceph: specially crafted XML payload on POST requests leads to DoS by crashing RGW CVE-2020-13379 — grafana: SSRF incorrect access control vulnerability allows unauthenticated users to make grafana send HTTP requests to any URL CVE-2020-27781 — ceph: User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila CVE-2021-3139 — tcmu-runner: SCSI target (LIO) write to any block on ILO backstore
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2021:1518
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1650209
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1652233
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1827262
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1829821
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1830329
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1832372
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1842390
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1843640
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1871035
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876551
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1882724
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1887661
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1894426
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1896392
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1896448
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1900109
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1901897
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1906293
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1915070
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1915078
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1916045
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1947072
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1948050
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_1518.json