Show plain JSON{"affected_release": [{"advisory": "RHSA-2020:3369", "cpe": "cpe:/a:redhat:service_mesh:1.1::el7", "impact": "low", "package": "kiali-0:v1.12.10.redhat2-1.el7", "product_name": "Openshift Service Mesh 1.1", "release_date": "2020-08-06T00:00:00Z"}, {"advisory": "RHSA-2020:3369", "cpe": "cpe:/a:redhat:service_mesh:1.1::el8", "impact": "low", "package": "ior-0:1.1.6-1.el8", "product_name": "OpenShift Service Mesh 1.1", "release_date": "2020-08-06T00:00:00Z"}, {"advisory": "RHSA-2020:3369", "cpe": "cpe:/a:redhat:service_mesh:1.1::el8", "impact": "low", "package": "servicemesh-0:1.1.6-1.el8", "product_name": "OpenShift Service Mesh 1.1", "release_date": "2020-08-06T00:00:00Z"}, {"advisory": "RHSA-2020:3369", "cpe": "cpe:/a:redhat:service_mesh:1.1::el8", "impact": "low", "package": "servicemesh-cni-0:1.1.6-1.el8", "product_name": "OpenShift Service Mesh 1.1", "release_date": "2020-08-06T00:00:00Z"}, {"advisory": "RHSA-2020:3369", "cpe": "cpe:/a:redhat:service_mesh:1.1::el8", "impact": "low", "package": "servicemesh-grafana-0:6.4.3-13.el8", "product_name": "OpenShift Service Mesh 1.1", "release_date": "2020-08-06T00:00:00Z"}, {"advisory": "RHSA-2020:3369", "cpe": "cpe:/a:redhat:service_mesh:1.1::el8", "impact": "low", "package": "servicemesh-operator-0:1.1.6-2.el8", "product_name": "OpenShift Service Mesh 1.1", "release_date": "2020-08-06T00:00:00Z"}, {"advisory": "RHSA-2020:3369", "cpe": "cpe:/a:redhat:service_mesh:1.1::el8", "impact": "low", "package": "servicemesh-prometheus-0:2.14.0-14.el8", "product_name": "OpenShift Service Mesh 1.1", "release_date": "2020-08-06T00:00:00Z"}], "bugzilla": {"description": "macaron: open redirect in the static handler", "id": "1850034", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1850034"}, "csaw": false, "cvss3": {"cvss3_base_score": "6.1", "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "status": "verified"}, "cwe": "CWE-601", "details": ["macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.", "A flaw was found in macaron. Path URLs aren't cleaned before being redirected creating an open redirect in the static handler."], "name": "CVE-2020-12666", "package_state": [{"cpe": "cpe:/a:redhat:ceph_storage:2", "fix_state": "Out of support scope", "package_name": "grafana", "product_name": "Red Hat Ceph Storage 2"}, {"cpe": "cpe:/a:redhat:ceph_storage:3", "fix_state": "Affected", "impact": "low", "package_name": "grafana", "product_name": "Red Hat Ceph Storage 3"}, {"cpe": "cpe:/a:redhat:ceph_storage:3", "fix_state": "Affected", "impact": "low", "package_name": "grafana-container", "product_name": "Red Hat Ceph Storage 3"}, {"cpe": "cpe:/a:redhat:ceph_storage:4", "fix_state": "Affected", "impact": "low", "package_name": "rhceph/rhceph-4-dashboard-rhel8", "product_name": "Red Hat Ceph Storage 4"}, {"cpe": "cpe:/a:redhat:openshift:3.11", "fix_state": "Fix deferred", "impact": "low", "package_name": "openshift3/grafana", "product_name": "Red Hat OpenShift Container Platform 3.11"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Fix deferred", "impact": "low", "package_name": "openshift4/ose-grafana", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:storage:3", "fix_state": "Affected", "impact": "low", "package_name": "grafana", "product_name": "Red Hat Storage 3"}], "public_date": "2020-05-06T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2020-12666\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-12666"], "statement": "This issue has a low impact on both OpenShift Container Platform and OpenShift Service Mesh grafana containers. As neither components make use of the Static handler the impact is Low. A future version of Grafana may use the Macaron Static handler so we may fix this in a future release.\nRed Hat Ceph Storage (RHCS) versions 3 and 4 use Grafana where the affected version of the macaron package is delivered. However the Static handler is not used by Ceph hence the impact by this vulnerability is Low. Ceph-2 has reached End of Extended Life Cycle Support and no longer fixing moderates/lows.", "threat_severity": "Moderate"}