CVE-2021-3509 log

Source
Severity Medium
Remote Yes
Type Cross-site scripting
Description
A security issue was found in ceph before version 15.2.12. In order to make the JWT token inaccessible through cross-site scripting (XSS), it was moved from localStorage to httpOnly Cookie (CVE-2020-27839). But token cookies are used in the body of the HTTP response for the documentation, which again makes it available to XSS.
Group Package Affected Fixed Severity Status Ticket
AVG-1826 ceph 15.2.10-1 15.2.12-1 High Fixed FS#70450
Date Advisory Group Package Severity Type
19 May 2021 ASA-202105-3 AVG-1826 ceph High multiple issues
References
https://bugzilla.redhat.com/show_bug.cgi?id=1950116
https://github.com/ceph/ceph/commit/7a1ca8d372da3b6a4fc3d221a0e5f72d1d61c27b