Lucene search

K
cvelistRedhatCVELIST:CVE-2020-1760
HistoryApr 23, 2020 - 12:00 a.m.

CVE-2020-1760

2020-04-2300:00:00
CWE-79
redhat
www.cve.org
1

5.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L

6.1 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

77.8%

A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.

CNA Affected

[
  {
    "vendor": "[UNKNOWN]",
    "product": "ceph",
    "versions": [
      {
        "version": "15.2.1",
        "status": "affected"
      },
      {
        "version": "14.2.9",
        "status": "affected"
      },
      {
        "version": "13.2.9",
        "status": "affected"
      }
    ]
  }
]

5.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L

6.1 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

77.8%