漏洞信息详情
多款Red Hat产品跨站脚本漏洞
漏洞简介
Red Hat Ceph Storage等都是美国红帽(Red Hat)公司的产品。Red Hat Ceph Storage是一套可扩展的、开放性的软件定义存储平台。Red Hat Ceph是一套Linux PB级分布式文件系统。Red Hat是一个操作系统。
Ceph 存在跨站脚本漏洞,该漏洞源于对通过JWT令牌在HTTP cookie中传递的用户提供的数据没有进行充分的无害化处理。远程攻击者可利用该漏洞可以在脆弱网站的上下文中在用户的浏览器中注入和执行任意的HTML和脚本代码。以下产品及版本受到影响:Ceph: 14.0.0, 14.0.1, 14.1.0, 14.1.1, 14.2.0, 14.2.1, 14.2.2, 14.2.3, 14.2.4, 14.2.5, 14.2.6, 14.2.7, 14.2.8, 14.2.9, 14.2.10, 14.2.11, 14.2.12, 14.2.13, 14.2.14, 14.2.15, 14.2.16, 14.2.17, 14.2.18, 14.2.19, 14.2.20, 15.0.0, 15.1.0, 15.1.1, 15.2.0, 15.2.1, 15.2.2, 15.2.3, 15.2.4, 15.2.5, 15.2.6, 15.2.7, 15.2.8, 15.2.9, 15.2.10, 15.2.11, 16.0.0, 16.1.0, 16.2.0, 16.2.1, 16.2.2, 16.2.3, 17.0.0。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-3509
参考网址
来源:MISC
链接:https://github.com/ceph/ceph/commit/7a1ca8d372da3b6a4fc3d221a0e5f72d1d61c27b
来源:MISC
链接:https://github.com/ceph/ceph/commit/adda853e64bdba1288d46bc7d462d23d8f2f10ca
来源:MISC
链接:https://github.com/ceph/ceph/commit/af3fffab3b0f13057134d96e5d481e400d8bfd27
来源:MISC
链接:https://github.com/ceph/ceph/blob/f1557e8f62d31883d3d34ae241a1a26af11d923f/src/pybind/mgr/dashboard/controllers/docs.py#L394-L409
来源:MISC
链接:https://bugzilla.redhat.com/show_bug.cgi?id=1950116
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2133
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163175/Red-Hat-Security-Advisory-2021-2445-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164753/Ubuntu-Security-Notice-USN-5128-1.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163288/Ubuntu-Security-Notice-USN-4998-1.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021051712
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3642
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2239
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-3509
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1934
受影响实体
暂无
补丁
- 多款Red Hat产品跨站脚本漏洞的修复措施<!--2021-5-17-->
还没有评论,来说两句吧...