View at Official debian advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2020-1760 not yet assigned priority: Debian including 1 source packages (ceph), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5.
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.