Project

General

Profile

Actions

Bug #43607

closed

Feature #47765: mgr/dashboard: security improvements

mgr/dashboard: fix improper URL checking

Added by Ernesto Puerta over 4 years ago. Updated about 3 years ago.

Status:
Resolved
Priority:
Immediate
Category:
General - Back-end
Target version:
% Done:

0%

Source:
Community (user)
Tags:
Backport:
nautilus
Regression:
No
Severity:
1 - critical
Reviewed:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

From https://github.com/rook/rook/issues/4635

Only release 14.2.5 and above show this behaviour (including master) introduced in https://github.com/ceph/ceph/pull/30694.

Assigned CVE-2020-1699

CWE-22


Related issues 1 (0 open1 closed)

Copied to Dashboard - Backport #43725: nautilus: mgr/dashboard: fix improper URL checkingResolvedErnesto PuertaActions
Actions

Also available in: Atom PDF