299 lines
12 KiB
JSON
299 lines
12 KiB
JSON
{
|
||
"Definition": [
|
||
{
|
||
"ID": "oval:org.altlinux.errata:def:20201757",
|
||
"Version": "oval:org.altlinux.errata:def:20201757",
|
||
"Class": "patch",
|
||
"Metadata": {
|
||
"Title": "ALT-PU-2020-1757: package `ceph` update to version 14.2.9-alt1",
|
||
"AffectedList": [
|
||
{
|
||
"Family": "unix",
|
||
"Platforms": [
|
||
"ALT Linux branch c10f1"
|
||
],
|
||
"Products": [
|
||
"ALT SP Workstation",
|
||
"ALT SP Server"
|
||
]
|
||
}
|
||
],
|
||
"References": [
|
||
{
|
||
"RefID": "ALT-PU-2020-1757",
|
||
"RefURL": "https://errata.altlinux.org/ALT-PU-2020-1757",
|
||
"Source": "ALTPU"
|
||
},
|
||
{
|
||
"RefID": "BDU:2021-03733",
|
||
"RefURL": "https://bdu.fstec.ru/vul/2021-03733",
|
||
"Source": "BDU"
|
||
},
|
||
{
|
||
"RefID": "CVE-2020-1759",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-1759",
|
||
"Source": "CVE"
|
||
},
|
||
{
|
||
"RefID": "CVE-2020-1760",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-1760",
|
||
"Source": "CVE"
|
||
}
|
||
],
|
||
"Description": "This update upgrades ceph to version 14.2.9-alt1. \nSecurity Fix(es):\n\n * BDU:2021-03733: Уязвимость системы хранения данных Ceph, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на целостность данных\n\n * CVE-2020-1759: A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.\n\n * CVE-2020-1760: A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.",
|
||
"Advisory": {
|
||
"From": "errata.altlinux.org",
|
||
"Severity": "Low",
|
||
"Rights": "Copyright 2024 BaseALT Ltd.",
|
||
"Issued": {
|
||
"Date": "2020-04-15"
|
||
},
|
||
"Updated": {
|
||
"Date": "2020-04-15"
|
||
},
|
||
"BDUs": [
|
||
{
|
||
"ID": "BDU:2021-03733",
|
||
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
|
||
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
|
||
"CWE": "CWE-79",
|
||
"Href": "https://bdu.fstec.ru/vul/2021-03733",
|
||
"Impact": "Low",
|
||
"Public": "20200407"
|
||
}
|
||
],
|
||
"CVEs": [
|
||
{
|
||
"ID": "CVE-2020-1759",
|
||
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
|
||
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
|
||
"CWE": "CWE-323",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-1759",
|
||
"Impact": "Low",
|
||
"Public": "20200413"
|
||
},
|
||
{
|
||
"ID": "CVE-2020-1760",
|
||
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
|
||
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
|
||
"CWE": "CWE-79",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-1760",
|
||
"Impact": "Low",
|
||
"Public": "20200423"
|
||
}
|
||
],
|
||
"AffectedCPEs": {
|
||
"CPEs": [
|
||
"cpe:/o:alt:spworkstation:10",
|
||
"cpe:/o:alt:spserver:10"
|
||
]
|
||
}
|
||
}
|
||
},
|
||
"Criteria": {
|
||
"Operator": "AND",
|
||
"Criterions": [
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:4001",
|
||
"Comment": "ALT Linux must be installed"
|
||
}
|
||
],
|
||
"Criterias": [
|
||
{
|
||
"Operator": "OR",
|
||
"Criterions": [
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757001",
|
||
"Comment": "ceph is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757002",
|
||
"Comment": "ceph-base is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757003",
|
||
"Comment": "ceph-common is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757004",
|
||
"Comment": "ceph-devel is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757005",
|
||
"Comment": "ceph-fuse is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757006",
|
||
"Comment": "ceph-mds is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757007",
|
||
"Comment": "ceph-mgr is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757008",
|
||
"Comment": "ceph-mgr-ansible is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757009",
|
||
"Comment": "ceph-mgr-dashboard is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757010",
|
||
"Comment": "ceph-mgr-deepsea is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757011",
|
||
"Comment": "ceph-mgr-diskprediction-cloud is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757012",
|
||
"Comment": "ceph-mgr-diskprediction-local is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757013",
|
||
"Comment": "ceph-mgr-influx is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757014",
|
||
"Comment": "ceph-mgr-insights is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757015",
|
||
"Comment": "ceph-mgr-k8sevents is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757016",
|
||
"Comment": "ceph-mgr-prometheus is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757017",
|
||
"Comment": "ceph-mgr-restful is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757018",
|
||
"Comment": "ceph-mgr-rook is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757019",
|
||
"Comment": "ceph-mgr-ssh is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757020",
|
||
"Comment": "ceph-mgr-telegraf is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757021",
|
||
"Comment": "ceph-mgr-zabbix is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757022",
|
||
"Comment": "ceph-mon is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757023",
|
||
"Comment": "ceph-osd is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757024",
|
||
"Comment": "ceph-radosgw is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757025",
|
||
"Comment": "ceph-resource-agents is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757026",
|
||
"Comment": "cephfs-shell is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757027",
|
||
"Comment": "grafana-dashboards-ceph is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757028",
|
||
"Comment": "libcephfs-devel is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757029",
|
||
"Comment": "libcephfs2 is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757030",
|
||
"Comment": "librados-devel is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757031",
|
||
"Comment": "librados2 is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757032",
|
||
"Comment": "libradosstriper-devel is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757033",
|
||
"Comment": "libradosstriper1 is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757034",
|
||
"Comment": "librbd-devel is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757035",
|
||
"Comment": "librbd1 is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757036",
|
||
"Comment": "librgw-devel is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757037",
|
||
"Comment": "librgw2 is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757038",
|
||
"Comment": "python3-module-ceph is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757039",
|
||
"Comment": "python3-module-ceph-argparse is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757040",
|
||
"Comment": "python3-module-ceph_volume is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757041",
|
||
"Comment": "python3-module-cephfs is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757042",
|
||
"Comment": "python3-module-rados is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757043",
|
||
"Comment": "python3-module-rbd is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757044",
|
||
"Comment": "python3-module-rgw is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757045",
|
||
"Comment": "rbd-fuse is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757046",
|
||
"Comment": "rbd-mirror is earlier than 0:14.2.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20201757047",
|
||
"Comment": "rbd-nbd is earlier than 0:14.2.9-alt1"
|
||
}
|
||
]
|
||
}
|
||
]
|
||
}
|
||
}
|
||
]
|
||
} |