CVE-2020-1760 update

This commit is contained in:
Dhananjay Arunesh 2020-04-23 11:06:31 +05:30
parent 278ebcbccb
commit 45f7cafc19
No known key found for this signature in database
GPG Key ID: 9B3D8FE350EC5D74

View File

@ -4,15 +4,77 @@
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2020-1760",
"ASSIGNER": "cve@mitre.org",
"STATE": "RESERVED"
"ASSIGNER": "darunesh@redhat.com"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "[UNKNOWN]",
"product": {
"product_data": [
{
"product_name": "ceph",
"version": {
"version_data": [
{
"version_value": "15.2.1"
},
{
"version_value": "14.2.9"
},
{
"version_value": "13.2.9"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-79"
}
]
}
]
},
"references": {
"reference_data": [
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1760",
"name": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1760",
"refsource": "CONFIRM"
},
{
"url": "https://www.openwall.com/lists/oss-security/2020/04/07/1"
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input."
}
]
},
"impact": {
"cvss": [
[
{
"vectorString": "5.8/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L",
"version": "3.0"
}
]
]
}
}