CVE-2020-1760: Canonical Ubuntu Linux

Medium severity, CVSS 6.1. EPSS: 1.6% chance of exploitation in the next 30 days.

A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 31 only
  • Linuxfoundation Ceph: before 14.2.21 (fixed in 14.2.21)
  • Red Hat Ceph Storage: version 3.0 only; version 4.0 only
  • Red Hat Openshift Container Platform: version 4.2 only

Published 2020-04-23. Last modified 2026-06-17.