A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ceph_storage | Redhat | 3.0 (including) | 3.0 (including) |
Ceph_storage | Redhat | 4.0 (including) | 4.0 (including) |
Openstack | Redhat | 15 (including) | 15 (including) |
Red Hat Ceph Storage 3.3 | RedHat | ceph-2:12.2.12-124.el7cp | * |
Red Hat Ceph Storage 3.3 | RedHat | ceph-ansible-0:3.2.48-1.el7cp | * |
Red Hat Ceph Storage 3.3 | RedHat | nfs-ganesha-0:2.7.4-13.el7cp | * |
Red Hat Ceph Storage 3 for Ubuntu | RedHat | * | |
Red Hat Ceph Storage 4.1 | RedHat | ceph-2:14.2.8-81.el7cp | * |
Red Hat Ceph Storage 4.1 | RedHat | ceph-ansible-0:4.0.25-1.el7cp | * |
Red Hat Ceph Storage 4.1 | RedHat | ceph-medic-0:1.0.8-1.el8cp | * |
Red Hat Ceph Storage 4.1 | RedHat | cockpit-ceph-installer-0:1.2-0.el7cp | * |
Red Hat Ceph Storage 4.1 | RedHat | nfs-ganesha-0:2.8.3-8.el8cp | * |
Ceph | Ubuntu | bionic | * |
Ceph | Ubuntu | devel | * |
Ceph | Ubuntu | eoan | * |
Ceph | Ubuntu | esm-infra-legacy/trusty | * |
Ceph | Ubuntu | focal | * |
Ceph | Ubuntu | groovy | * |
Ceph | Ubuntu | hirsute | * |
Ceph | Ubuntu | impish | * |
Ceph | Ubuntu | jammy | * |
Ceph | Ubuntu | kinetic | * |
Ceph | Ubuntu | lunar | * |
Ceph | Ubuntu | mantic | * |
Ceph | Ubuntu | noble | * |
Ceph | Ubuntu | oracular | * |
Ceph | Ubuntu | precise/esm | * |
Ceph | Ubuntu | trusty | * |
Ceph | Ubuntu | trusty/esm | * |
Ceph | Ubuntu | upstream | * |
Ceph | Ubuntu | xenial | * |