RHSA-2023:5693MediumCVSS 6.3

Red Hat Security Advisory: Red Hat Ceph Storage 6.1 security, enhancement, and bug fix update

Published
October 12, 2023
Last Modified
August 4, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2018-14041 — bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy CVE-2018-20676 — bootstrap: XSS in the tooltip data-viewport attribute CVE-2018-20677 — bootstrap: XSS in the affix configuration target property CVE-2023-43040 — rgw: improperly verified POST keys CVE-2023-46159 — ceph: RGW crash upon misconfigured CORS rule

🎯 Affected products158

  • Red Hat Ceph Storage 6.1 Tools
  • ceph-2:17.2.6-148.el9cp.src as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-base-2:17.2.6-148.el9cp.ppc64le as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-base-2:17.2.6-148.el9cp.s390x as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-base-2:17.2.6-148.el9cp.x86_64 as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-base-debuginfo-2:17.2.6-148.el9cp.ppc64le as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-base-debuginfo-2:17.2.6-148.el9cp.s390x as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-base-debuginfo-2:17.2.6-148.el9cp.x86_64 as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-common-2:17.2.6-148.el9cp.ppc64le as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-common-2:17.2.6-148.el9cp.s390x as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-common-2:17.2.6-148.el9cp.x86_64 as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-common-debuginfo-2:17.2.6-148.el9cp.ppc64le as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-common-debuginfo-2:17.2.6-148.el9cp.s390x as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-common-debuginfo-2:17.2.6-148.el9cp.x86_64 as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-debuginfo-2:17.2.6-148.el9cp.ppc64le as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-debuginfo-2:17.2.6-148.el9cp.s390x as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-debuginfo-2:17.2.6-148.el9cp.x86_64 as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-debugsource-2:17.2.6-148.el9cp.ppc64le as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-debugsource-2:17.2.6-148.el9cp.s390x as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-debugsource-2:17.2.6-148.el9cp.x86_64 as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-exporter-debuginfo-2:17.2.6-148.el9cp.ppc64le as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-exporter-debuginfo-2:17.2.6-148.el9cp.s390x as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-exporter-debuginfo-2:17.2.6-148.el9cp.x86_64 as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-fuse-2:17.2.6-148.el9cp.ppc64le as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-fuse-2:17.2.6-148.el9cp.s390x as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-fuse-2:17.2.6-148.el9cp.x86_64 as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-fuse-debuginfo-2:17.2.6-148.el9cp.ppc64le as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-fuse-debuginfo-2:17.2.6-148.el9cp.s390x as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-fuse-debuginfo-2:17.2.6-148.el9cp.x86_64 as a component of Red Hat Ceph Storage 6.1 Tools
  • ceph-immutable-object-cache-2:17.2.6-148.el9cp.ppc64le as a component of Red Hat Ceph Storage 6.1 Tools
  • +128 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/2789521 and https://access.redhat.com/documentation/en-us/red_hat_ceph_storage/6 For supported configurations, refer to: https://access.redhat.com/articles/1548993

🔗 References (59)