CVE-2020-1760
Publication date 23 April 2020
Last updated 18 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| ceph | ||
| 24.04 LTS noble |
Not affected
|
|
| 22.04 LTS jammy |
Not affected
|
|
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic |
Fixed 12.2.13-0ubuntu0.18.04.4
|
|
| 16.04 LTS xenial |
Fixed 10.2.11-0ubuntu0.16.04.3
|
|
| 14.04 LTS trusty | Ignored end of standard support |
Patch details
| Package | Patch details |
|---|---|
| ceph |
Severity score breakdown
CVSS version: CVSS v3.0
Base score
5.8 · Medium
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
References
Related Ubuntu Security Notices (USN)
- USN-4528-1
- Ceph vulnerabilities
- 22 September 2020