BIT-ceph-2020-1760

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/ceph/BIT-ceph-2020-1760.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-ceph-2020-1760
Aliases
Published
2026-03-20T09:05:40.784Z
Modified
2026-03-20T10:00:10.345816Z
Summary
[none]
Details

A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.

Database specific
{
    "cpes": [
        "cpe:2.3:a:linuxfoundation:ceph:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / ceph

Package

Name
ceph
Purl
pkg:bitnami/ceph

Severity

  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
14.2.21

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/ceph/BIT-ceph-2020-1760.json"