openSUSE-SU-2021:0833-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:0833-1
openSUSE-SU-2021:0833-1
Summary: Security update for ceph
Details: This update for ceph fixes the following issues: - Update to 15.2.12-83-g528da226523: - (CVE-2021-3509) fix cookie injection issue (bsc#1186021) - (CVE-2021-3531) RGWSwiftWebsiteHandler::is_web_dir checks empty subdir_name (bsc#1186020) - (CVE-2021-3524) sanitize \r in s3 CORSConfiguration’s ExposeHeader (bsc#1185619) This update was imported from the SUSE:SLE-15-SP2:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/SVZR2UDWM64LU6NNFZNHXJWWFA6W2ZDV/, https://bugzilla.suse.com/1185619, https://bugzilla.suse.com/1186020, https://bugzilla.suse.com/1186021, https://www.suse.com/security/cve/CVE-2021-3509, https://www.suse.com/security/cve/CVE-2021-3524, https://www.suse.com/security/cve/CVE-2021-3531
Affected packages
Package
Name: ceph
Purl: pkg:rpm/opensuse/ceph&distro=openSUSE%20Leap%2015.2
Affected ranges
Type: ECOSYSTEM
Events:
