RHSA-2023:3642HighCVSS 9.8

Red Hat Security Advisory: Red Hat Ceph Storage 6.1 Container security and bug fix update

Published
June 15, 2023
Last Modified
May 23, 2026

🔗 CVE IDs covered (35)

📋 Description

CVE-2021-42581 — ramda: prototype poisoning CVE-2022-1650 — eventsource: Exposure of Sensitive Information CVE-2022-1705 — golang: net/http: improper sanitization of Transfer-Encoding header CVE-2022-2880 — golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters CVE-2022-21680 — marked: regular expression block.def may lead Denial of Service CVE-2022-21681 — marked: regular expression inline.reflinkSearch may lead Denial of Service CVE-2022-23498 — grafana: Use of Cache Containing Sensitive Information CVE-2022-24675 — golang: encoding/pem: fix stack overflow in Decode CVE-2022-24785 — Moment.js: Path traversal in moment.locale CVE-2022-26148 — grafana: An information leak issue was discovered in Grafana through 7.3.4, when integrated with Zabbix CVE-2022-27664 — golang: net/http: handle server errors after sending GOAWAY CVE-2022-28131 — golang: encoding/xml: stack exhaustion in Decoder.Skip CVE-2022-28327 — golang: crypto/elliptic: panic caused by oversized scalar CVE-2022-29526 — golang: syscall: faccessat checks wrong group CVE-2022-30629 — golang: crypto/tls: session tickets lack random ticket_age_add CVE-2022-30630 — golang: io/fs: stack exhaustion in Glob CVE-2022-30631 — golang: compress/gzip: stack exhaustion in Reader.Read CVE-2022-30632 — golang: path/filepath: stack exhaustion in Glob CVE-2022-30633 — golang: encoding/xml: stack exhaustion in Unmarshal CVE-2022-30635 — golang: encoding/gob: stack exhaustion in Decoder.Decode CVE-2022-31097 — grafana: stored XSS vulnerability CVE-2022-31107 — grafana: OAuth account takeover CVE-2022-31123 — grafana: plugin signature bypass CVE-2022-31130 — grafana: data source and plugin proxy endpoints leaking authentication tokens to some destination plugins CVE-2022-32148 — golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working CVE-2022-32189 — golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service CVE-2022-32190 — golang: net/url: JoinPath does not strip relative path components in all circumstances CVE-2022-35957 — grafana: Escalation from admin to server admin when auth proxy is used CVE-2022-39201 — grafana: Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins CVE-2022-39229 — grafana: using email as a username can block other users from signing in CVE-2022-39306 — grafana: email addresses and usernames cannot be trusted CVE-2022-39307 — grafana: User enumeration via forget password CVE-2022-39324 — grafana: Spoofing of the originalUrl parameter of snapshots CVE-2022-41715 — golang: regexp/syntax: limit memory used by parsing regexps CVE-2022-41912 — crewjam/saml: Authentication bypass when processing SAML responses containing multiple Assertion elements

🔗 References (42)