Alpine: ceph: security update to 14.2.8-r0 (deprecated)

medium Tenable Cloud Security Plugin ID 400393

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A
nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow
an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a
session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and
integrity attacks. (CVE-2020-1759)

- A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon
S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted
input. (CVE-2020-1760)

See Also

https://git.alpinelinux.org/aports/commit/?id=2dda68448cfdb97f20e4a2e56b30e5f6e9771121

https://git.alpinelinux.org/aports/commit/?id=e86921098008f77406780117b6483f1e5f31f1b5

Plugin Details

Severity: Medium

ID: 400393

Version: Revision 1.23

Type: Local

Published: 8/16/2023

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.04

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2020-1759

CVSS v3

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/3/2020

Vulnerability Publication Date: 4/13/2020

Reference Information

CVE: CVE-2020-1759, CVE-2020-1760