blob: 7e865e9b247fc7c9e427252ff2e2f6bb5033cb68 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
|
.. _CVE-2021-3509:
CVE-2021-3509: Dashboard XSS via token cookie
=============================================
* `NIST information page <https://nvd.nist.gov/vuln/detail/CVE-2021-3509>`_
The Ceph Dashboard was vulnerable to an XSS attack that could expose the authentication
cookie to other sites.
Affected versions
-----------------
* Octopus v15.2.0 and later
Fixed versions
--------------
* Pacific v16.2.4 (and later)
* Octopus v15.2.12 (and later)
* Nautilus v14.2.21 (and later)
Recommendations
---------------
All users of the Ceph dashboard should upgrade.
|