RHSA-2021:0083: Important: Red Hat Ceph Storage 4.2 security and bug fix update
The rhceph-4.2 image is based on Red Hat Ceph Storage 4.2 and Red Hat Enterprise Linux.Security Fix(es): grafana: SSRF incorrect access control vulnerability allows unauthenticated users to make grafana send HTTP requests to any URL (CVE-2020-13379) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es):Users are directed to the Red Hat Ceph Storage 4.2 Release Notes for information on the most significant of these changes:https://access.redhat.com/documentation/en-us/redhatcephstorage/4.2/html /releasenotes/All users of the rhceph-4.2 image are advised to pull this updated image from the Red Hat Ecosystem Catalog.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:0083?
The severity of RHSA-2021:0083 is classified as important.
What vulnerability is addressed by RHSA-2021:0083?
RHSA-2021:0083 addresses a Server-Side Request Forgery (SSRF) vulnerability in Grafana, identified as CVE-2020-13379.
How do I fix RHSA-2021:0083?
To fix RHSA-2021:0083, you need to update to the latest version of the affected packages as advised in the security announcement.
What systems are affected by RHSA-2021:0083?
The RHSA-2021:0083 vulnerability affects the rhceph-4.2 image based on Red Hat Ceph Storage 4.2 and Red Hat Enterprise Linux.
Is there a workaround for RHSA-2021:0083?
There are no known workarounds for RHSA-2021:0083, so applying the security update is recommended.