SUSE-SU-2021:1835-1
Dashboard / Vulnerabilities / SUSE-SU-2021:1835-1
SUSE-SU-2021:1835-1
Summary: Security update for ceph
Details: This update for ceph fixes the following issues: - Update to 15.2.12-83-g528da226523: - (CVE-2021-3509) fix cookie injection issue (bsc#1186021) - (CVE-2021-3531) RGWSwiftWebsiteHandler::is_web_dir checks empty subdir_name (bsc#1186020) - (CVE-2021-3524) sanitize \r in s3 CORSConfiguration’s ExposeHeader (bsc#1185619)
References: https://www.suse.com/support/update/announcement/2021/suse-su-20211835-1/, https://bugzilla.suse.com/1185619, https://bugzilla.suse.com/1186020, https://bugzilla.suse.com/1186021, https://www.suse.com/security/cve/CVE-2021-3509, https://www.suse.com/security/cve/CVE-2021-3524, https://www.suse.com/security/cve/CVE-2021-3531
Affected packages
Package
Name: ceph
Purl: pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOS
Affected ranges
Type: ECOSYSTEM
Events:
