Index: security/vuxml/vuln.xml =================================================================== --- security/vuxml/vuln.xml (revision 545072) +++ security/vuxml/vuln.xml (working copy) @@ -58,6 +58,37 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + ceph14 -- HTTP header injection via CORS ExposeHeader tag + + + ceph14 + 14.2.11 + + + + +

Red Hat bugzilla reports:

+
+

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). + The vulnerability is related to the injection of HTTP headers via a CORS + ExposeHeader tag. The newline character in the ExposeHeader tag in the + CORS configuration file generates a header injection in the response + when the CORS request is made.

+
+ +
+ + https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10753 + CVE-2020-10753 + ports/248673 + + + 2020-05-27 + 2020-08-16 + +
+ snmptt -- malicious shell code