CVE-2020-27839

Description

A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browsers localStorage which is potentially vulnerable to attackers via XSS attacks. The highest threat from this vulnerability is to data confidentiality and integrity.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.335

Associated Vulnerability

VulnerabilityOS Platform
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-ansible-4.0.57-1.el7cp.noarch.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-ansible-4.0.57-1.el8cp.noarch.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-base-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-base-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-common-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-common-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-debugsource-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-fuse-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-fuse-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-grafana-dashboards-14.2.11-181.el7cp.noarch.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-grafana-dashboards-14.2.11-181.el8cp.noarch.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-iscsi-3.4-4.el7cp.noarch.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-iscsi-3.4-4.el8cp.noarch.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-mds-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-mds-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-radosgw-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-radosgw-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-selinux-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-selinux-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libcephfs-devel-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libcephfs-devel-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libcephfs2-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libcephfs2-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librados-devel-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librados-devel-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librados2-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librados2-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libradospp-devel-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libradospp-devel-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libradosstriper1-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libradosstriper1-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librbd-devel-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librbd-devel-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librbd1-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librbd1-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librgw-devel-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librgw-devel-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librgw2-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librgw2-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libtcmu-1.5.2-4.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libtcmu-1.5.2-4.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python-ceph-argparse-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python-cephfs-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python-rados-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python-rbd-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python-rgw-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python3-ceph-argparse-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python3-cephfs-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python3-rados-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python3-rbd-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python3-rgw-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update rbd-mirror-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update rbd-mirror-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update rbd-nbd-14.2.11-181.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update rbd-nbd-14.2.11-181.el8cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update tcmu-runner-1.5.2-4.el7cp.x86_64.rpmLinux
(RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update tcmu-runner-1.5.2-4.el8cp.x86_64.rpmLinux
distributed storage and file system (USN-4998-1) ceph_15.2.12-0ubuntu0.20.04.1_amd64.debLinux
distributed storage and file system (USN-4998-1) ceph_15.2.12-0ubuntu0.20.10.1_amd64.debLinux
distributed storage and file system (USN-4998-1) cephadm_15.2.12-0ubuntu0.20.04.1_amd64.debLinux
distributed storage and file system (USN-4998-1) cephadm_15.2.12-0ubuntu0.20.10.1_amd64.debLinux
distributed storage and file system (USN-4998-1) radosgw_15.2.12-0ubuntu0.20.04.1_amd64.debLinux
distributed storage and file system (USN-4998-1) radosgw_15.2.12-0ubuntu0.20.10.1_amd64.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr_15.2.12-0ubuntu0.20.04.1_amd64.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr_15.2.12-0ubuntu0.20.10.1_amd64.debLinux
distributed storage and file system (USN-4998-1) ceph-base_15.2.12-0ubuntu0.20.04.1_amd64.debLinux
distributed storage and file system (USN-4998-1) ceph-base_15.2.12-0ubuntu0.20.10.1_amd64.debLinux
distributed storage and file system (USN-4998-1) ceph-common_15.2.12-0ubuntu0.20.04.1_amd64.debLinux
distributed storage and file system (USN-4998-1) ceph-common_15.2.12-0ubuntu0.20.10.1_amd64.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-rook_15.2.12-0ubuntu0.20.04.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-rook_15.2.12-0ubuntu0.20.10.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-cephadm_15.2.12-0ubuntu0.20.04.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-cephadm_15.2.12-0ubuntu0.20.10.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-dashboard_15.2.12-0ubuntu0.20.04.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-dashboard_15.2.12-0ubuntu0.20.10.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-k8sevents_15.2.12-0ubuntu0.20.04.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-k8sevents_15.2.12-0ubuntu0.20.10.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-modules-core_15.2.12-0ubuntu0.20.04.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-modules-core_15.2.12-0ubuntu0.20.10.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-cloud_15.2.12-0ubuntu0.20.04.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-cloud_15.2.12-0ubuntu0.20.10.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-local_15.2.12-0ubuntu0.20.04.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-local_15.2.12-0ubuntu0.20.10.1_all.debLinux
distributed storage and file system (USN-4998-1) cephadm_15.2.12-0ubuntu0.20.04.1_amd64.debLinux
distributed storage and file system (USN-4998-1) radosgw_15.2.12-0ubuntu0.20.04.1_amd64.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr_15.2.12-0ubuntu0.20.04.1_amd64.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-rook_15.2.12-0ubuntu0.20.04.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-cephadm_15.2.12-0ubuntu0.20.04.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-dashboard_15.2.12-0ubuntu0.20.04.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-k8sevents_15.2.12-0ubuntu0.20.04.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-modules-core_15.2.12-0ubuntu0.20.04.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-cloud_15.2.12-0ubuntu0.20.04.1_all.debLinux
distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-local_15.2.12-0ubuntu0.20.04.1_all.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234