MEDIUM · 5.8

CVE-2020-1760

A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of...

Vulnerability Description

A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.

CVSS Score

5.8

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
LinuxfoundationCeph< 14.2.21
RedhatCeph Storage3.0
RedhatOpenshift Container Platform4.2
FedoraprojectFedora31
CanonicalUbuntu Linux16.04
DebianDebian Linux9.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-1760?

CVE-2020-1760 is a vulnerability with a CVSS score of 5.8 (MEDIUM). A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of...

How severe is CVE-2020-1760?

CVE-2020-1760 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-1760?

Check the references section above for vendor advisories and patch information. Affected products include: Linuxfoundation Ceph, Redhat Ceph Storage, Redhat Openshift Container Platform, Fedoraproject Fedora, Canonical Ubuntu Linux.