Database/Control plane, storage & DevOps
Ceph RGW: HTTP header injection via a newline in the CORS ExposeHeader tag
CVSS 6.5CVE-2021-3524Control plane, storage & DevOpscurated
Impact
HTTP header injection via a newline in the CORS ExposeHeader tag
Who can reach it
Network (remote)
What to do
Control-plane: RGW upgrade only; no OSD disruption
References
Related entries
- Ceph: Key length incorrectly passed to the encryption algorithmCVE-2021-3979 · CephMedium
- Slurm (slurmdbd, AccountingStoreFlags=job_script / job_env): When the site turns on job-script and job-environmentCVE-2021-43337 · Slurm (slurmdbd, AccountingStoreFlags=job_script / job_env)Medium
- IBM Spectrum Scale Data Access Services (DAS): An authenticated DAS user inserts code that manipulates clusterCVE-2022-22411 · IBM Spectrum Scale Data Access Services (DAS)Medium
- FlyteAdmin (external IdP access token / ID token expiration check): FlyteAdmin does not enforce expiry on access and IDCVE-2022-31145 · FlyteAdmin (external IdP access token / ID token expiration check)Medium
- HashiCorp Consul: Internal RPC endpoint does not check multiple SAN URIs in a CSRCVE-2022-40716 · HashiCorp ConsulMedium
- AMD IOMMU - not re-initialized during DRTM (AMD-SB-3003): The IOMMU is not re-initialized during a Dynamic Root ofCVE-2023-20591 · AMD IOMMU - not re-initialized during DRTM (AMD-SB-3003)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.