Back

HIGH

ceph: improper URL checking leads to information disclosure

Published Apr 21, 2020

Description

A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to cause information disclosure on the host machine running the Ceph dashboard.

Affected products

Remediation

Red Hat statement

This vulnerability affects following Ceph versions of upstream - v14.2.5, v14.2.6, v15.0.0 and it has been fixed in v14.2.7 and v15.1.0. Red Hat Ceph Storage never shipped the affected versions of Ceph hence not affected.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 21, 2020
Updated Aug 4, 2024
Reserved Nov 27, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 15, 2020