<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">ceph-16.2.6.45+g8fda9838398-1.1 on GA media</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2024:10676-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-06-15T00:00:00Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-06-15T00:00:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-06-15T00:00:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">ceph-16.2.6.45+g8fda9838398-1.1 on GA media</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">These are all security issues fixed in the ceph-16.2.6.45+g8fda9838398-1.1 package on the GA media of openSUSE Tumbleweed.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-Tumbleweed-2024-10676</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-16818/</URL>
      <Description>SUSE CVE CVE-2017-16818 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-10861/</URL>
      <Description>SUSE CVE CVE-2018-10861 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-1128/</URL>
      <Description>SUSE CVE CVE-2018-1128 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-16889/</URL>
      <Description>SUSE CVE CVE-2018-16889 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-10222/</URL>
      <Description>SUSE CVE CVE-2019-10222 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-3821/</URL>
      <Description>SUSE CVE CVE-2019-3821 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-10736/</URL>
      <Description>SUSE CVE CVE-2020-10736 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-1759/</URL>
      <Description>SUSE CVE CVE-2020-1759 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-1760/</URL>
      <Description>SUSE CVE CVE-2020-1760 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-20288/</URL>
      <Description>SUSE CVE CVE-2021-20288 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-3509/</URL>
      <Description>SUSE CVE CVE-2021-3509 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-3524/</URL>
      <Description>SUSE CVE CVE-2021-3524 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-3531/</URL>
      <Description>SUSE CVE CVE-2021-3531 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="ceph-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-16.2.6.45+g8fda9838398-1.1">ceph-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-base-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-base-16.2.6.45+g8fda9838398-1.1">ceph-base-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-common-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-common-16.2.6.45+g8fda9838398-1.1">ceph-common-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-fuse-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-fuse-16.2.6.45+g8fda9838398-1.1">ceph-fuse-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1">ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1">ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mds-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-mds-16.2.6.45+g8fda9838398-1.1">ceph-mds-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mgr-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-mgr-16.2.6.45+g8fda9838398-1.1">ceph-mgr-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1">ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1">ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1">ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1">ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1">ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1">ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mon-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-mon-16.2.6.45+g8fda9838398-1.1">ceph-mon-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-osd-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-osd-16.2.6.45+g8fda9838398-1.1">ceph-osd-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1">ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-radosgw-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="ceph-radosgw-16.2.6.45+g8fda9838398-1.1">ceph-radosgw-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cephadm-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="cephadm-16.2.6.45+g8fda9838398-1.1">cephadm-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cephfs-mirror-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="cephfs-mirror-16.2.6.45+g8fda9838398-1.1">cephfs-mirror-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cephfs-shell-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="cephfs-shell-16.2.6.45+g8fda9838398-1.1">cephfs-shell-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cephfs-top-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="cephfs-top-16.2.6.45+g8fda9838398-1.1">cephfs-top-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcephfs-devel-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="libcephfs-devel-16.2.6.45+g8fda9838398-1.1">libcephfs-devel-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcephfs2-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="libcephfs2-16.2.6.45+g8fda9838398-1.1">libcephfs2-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcephsqlite-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="libcephsqlite-16.2.6.45+g8fda9838398-1.1">libcephsqlite-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1">libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="librados-devel-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="librados-devel-16.2.6.45+g8fda9838398-1.1">librados-devel-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="librados2-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="librados2-16.2.6.45+g8fda9838398-1.1">librados2-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libradospp-devel-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="libradospp-devel-16.2.6.45+g8fda9838398-1.1">libradospp-devel-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="librbd-devel-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="librbd-devel-16.2.6.45+g8fda9838398-1.1">librbd-devel-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="librbd1-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="librbd1-16.2.6.45+g8fda9838398-1.1">librbd1-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="librgw-devel-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="librgw-devel-16.2.6.45+g8fda9838398-1.1">librgw-devel-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="librgw2-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="librgw2-16.2.6.45+g8fda9838398-1.1">librgw2-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1">python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-ceph-common-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="python3-ceph-common-16.2.6.45+g8fda9838398-1.1">python3-ceph-common-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-cephfs-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="python3-cephfs-16.2.6.45+g8fda9838398-1.1">python3-cephfs-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-rados-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="python3-rados-16.2.6.45+g8fda9838398-1.1">python3-rados-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-rbd-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="python3-rbd-16.2.6.45+g8fda9838398-1.1">python3-rbd-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-rgw-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="python3-rgw-16.2.6.45+g8fda9838398-1.1">python3-rgw-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rados-objclass-devel-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="rados-objclass-devel-16.2.6.45+g8fda9838398-1.1">rados-objclass-devel-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rbd-fuse-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="rbd-fuse-16.2.6.45+g8fda9838398-1.1">rbd-fuse-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rbd-mirror-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="rbd-mirror-16.2.6.45+g8fda9838398-1.1">rbd-mirror-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rbd-nbd-16.2.6.45+g8fda9838398-1.1">
      <FullProductName ProductID="rbd-nbd-16.2.6.45+g8fda9838398-1.1">rbd-nbd-16.2.6.45+g8fda9838398-1.1</FullProductName>
    </Branch>
    <Relationship ProductReference="ceph-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-16.2.6.45+g8fda9838398-1.1">ceph-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-base-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-base-16.2.6.45+g8fda9838398-1.1">ceph-base-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-common-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-common-16.2.6.45+g8fda9838398-1.1">ceph-common-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-fuse-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-fuse-16.2.6.45+g8fda9838398-1.1">ceph-fuse-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1">ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1">ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mds-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mds-16.2.6.45+g8fda9838398-1.1">ceph-mds-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mgr-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mgr-16.2.6.45+g8fda9838398-1.1">ceph-mgr-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1">ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1">ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1">ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1">ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1">ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1">ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mon-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mon-16.2.6.45+g8fda9838398-1.1">ceph-mon-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-osd-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-osd-16.2.6.45+g8fda9838398-1.1">ceph-osd-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1">ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-radosgw-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-radosgw-16.2.6.45+g8fda9838398-1.1">ceph-radosgw-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="cephadm-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:cephadm-16.2.6.45+g8fda9838398-1.1">cephadm-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="cephfs-mirror-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:cephfs-mirror-16.2.6.45+g8fda9838398-1.1">cephfs-mirror-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="cephfs-shell-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:cephfs-shell-16.2.6.45+g8fda9838398-1.1">cephfs-shell-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="cephfs-top-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:cephfs-top-16.2.6.45+g8fda9838398-1.1">cephfs-top-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcephfs-devel-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libcephfs-devel-16.2.6.45+g8fda9838398-1.1">libcephfs-devel-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcephfs2-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libcephfs2-16.2.6.45+g8fda9838398-1.1">libcephfs2-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcephsqlite-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libcephsqlite-16.2.6.45+g8fda9838398-1.1">libcephsqlite-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1">libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="librados-devel-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:librados-devel-16.2.6.45+g8fda9838398-1.1">librados-devel-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="librados2-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:librados2-16.2.6.45+g8fda9838398-1.1">librados2-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libradospp-devel-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libradospp-devel-16.2.6.45+g8fda9838398-1.1">libradospp-devel-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="librbd-devel-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:librbd-devel-16.2.6.45+g8fda9838398-1.1">librbd-devel-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="librbd1-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:librbd1-16.2.6.45+g8fda9838398-1.1">librbd1-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="librgw-devel-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:librgw-devel-16.2.6.45+g8fda9838398-1.1">librgw-devel-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="librgw2-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:librgw2-16.2.6.45+g8fda9838398-1.1">librgw2-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1">python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-ceph-common-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:python3-ceph-common-16.2.6.45+g8fda9838398-1.1">python3-ceph-common-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-cephfs-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:python3-cephfs-16.2.6.45+g8fda9838398-1.1">python3-cephfs-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-rados-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:python3-rados-16.2.6.45+g8fda9838398-1.1">python3-rados-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-rbd-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:python3-rbd-16.2.6.45+g8fda9838398-1.1">python3-rbd-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-rgw-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:python3-rgw-16.2.6.45+g8fda9838398-1.1">python3-rgw-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="rados-objclass-devel-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:rados-objclass-devel-16.2.6.45+g8fda9838398-1.1">rados-objclass-devel-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="rbd-fuse-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:rbd-fuse-16.2.6.45+g8fda9838398-1.1">rbd-fuse-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="rbd-mirror-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:rbd-mirror-16.2.6.45+g8fda9838398-1.1">rbd-mirror-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="rbd-nbd-16.2.6.45+g8fda9838398-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:rbd-nbd-16.2.6.45+g8fda9838398-1.1">rbd-nbd-16.2.6.45+g8fda9838398-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an invalid profile to the admin API, related to rgw/rgw_iam_policy.cc, rgw/rgw_basic_types.h, and rgw/rgw_iam_types.h.</Note>
    </Notes>
    <CVE>CVE-2017-16818</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ceph-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-base-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mds-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mon-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-osd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-radosgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-shell-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-top-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libradospp-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd1-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-cephfs-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rados-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rbd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rados-objclass-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-nbd-16.2.6.45+g8fda9838398-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:C</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-16818.html</URL>
        <Description>CVE-2017-16818</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1063014</URL>
        <Description>SUSE Bug 1063014</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1069253</URL>
        <Description>SUSE Bug 1069253</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.</Note>
    </Notes>
    <CVE>CVE-2018-10861</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ceph-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-base-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mds-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mon-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-osd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-radosgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-shell-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-top-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libradospp-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd1-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-cephfs-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rados-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rbd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rados-objclass-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-nbd-16.2.6.45+g8fda9838398-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.5</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-10861.html</URL>
        <Description>CVE-2018-10861</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1099162</URL>
        <Description>SUSE Bug 1099162</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1114710</URL>
        <Description>SUSE Bug 1114710</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.</Note>
    </Notes>
    <CVE>CVE-2018-1128</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ceph-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-base-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mds-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mon-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-osd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-radosgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-shell-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-top-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libradospp-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd1-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-cephfs-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rados-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rbd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rados-objclass-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-nbd-16.2.6.45+g8fda9838398-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.4</BaseScore>
        <Vector>AV:A/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-1128.html</URL>
        <Description>CVE-2018-1128</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1096748</URL>
        <Description>SUSE Bug 1096748</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1114710</URL>
        <Description>SUSE Bug 1114710</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1177843</URL>
        <Description>SUSE Bug 1177843</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1177859</URL>
        <Description>SUSE Bug 1177859</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.</Note>
    </Notes>
    <CVE>CVE-2018-16889</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ceph-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-base-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mds-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mon-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-osd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-radosgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-shell-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-top-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libradospp-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd1-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-cephfs-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rados-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rbd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rados-objclass-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-nbd-16.2.6.45+g8fda9838398-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-16889.html</URL>
        <Description>CVE-2018-16889</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1121567</URL>
        <Description>SUSE Bug 1121567</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.</Note>
    </Notes>
    <CVE>CVE-2019-10222</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ceph-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-base-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mds-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mon-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-osd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-radosgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-shell-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-top-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libradospp-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd1-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-cephfs-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rados-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rbd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rados-objclass-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-nbd-16.2.6.45+g8fda9838398-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-10222.html</URL>
        <Description>CVE-2019-10222</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1139399</URL>
        <Description>SUSE Bug 1139399</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1145093</URL>
        <Description>SUSE Bug 1145093</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust file descriptors for ceph-radosgw service resulting in a remote denial of service.</Note>
    </Notes>
    <CVE>CVE-2019-3821</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ceph-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-base-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mds-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mon-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-osd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-radosgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-shell-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-top-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libradospp-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd1-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-cephfs-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rados-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rbd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rados-objclass-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-nbd-16.2.6.45+g8fda9838398-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-3821.html</URL>
        <Description>CVE-2019-3821</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1125080</URL>
        <Description>SUSE Bug 1125080</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restrict access, resulting in gaining access to unauthorized resources. This flaw allows an authenticated client to modify the configuration and possibly conduct further attacks.</Note>
    </Notes>
    <CVE>CVE-2020-10736</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ceph-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-base-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mds-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mon-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-osd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-radosgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-shell-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-top-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libradospp-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd1-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-cephfs-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rados-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rbd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rados-objclass-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-nbd-16.2.6.45+g8fda9838398-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.2</BaseScore>
        <Vector>AV:A/AC:L/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-10736.html</URL>
        <Description>CVE-2020-10736</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1170021</URL>
        <Description>SUSE Bug 1170021</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.</Note>
    </Notes>
    <CVE>CVE-2020-1759</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ceph-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-base-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mds-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mon-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-osd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-radosgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-shell-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-top-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libradospp-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd1-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-cephfs-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rados-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rbd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rados-objclass-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-nbd-16.2.6.45+g8fda9838398-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-1759.html</URL>
        <Description>CVE-2020-1759</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1166403</URL>
        <Description>SUSE Bug 1166403</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.</Note>
    </Notes>
    <CVE>CVE-2020-1760</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ceph-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-base-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mds-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mon-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-osd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-radosgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-shell-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-top-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libradospp-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd1-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-cephfs-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rados-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rbd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rados-objclass-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-nbd-16.2.6.45+g8fda9838398-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-1760.html</URL>
        <Description>CVE-2020-1760</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1166484</URL>
        <Description>SUSE Bug 1166484</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of any user to request a global_id previously associated with another user, as ceph does not force the reuse of old keys to generate new ones. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.</Note>
    </Notes>
    <CVE>CVE-2021-20288</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ceph-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-base-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mds-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mon-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-osd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-radosgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-shell-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-top-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libradospp-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd1-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-cephfs-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rados-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rbd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rados-objclass-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-nbd-16.2.6.45+g8fda9838398-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.5</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-20288.html</URL>
        <Description>CVE-2021-20288</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1183074</URL>
        <Description>SUSE Bug 1183074</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1205049</URL>
        <Description>SUSE Bug 1205049</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In response to CVE-2020-27839, the JWT token was moved from localStorage to an httpOnly cookie. However, token cookies are used in the body of the HTTP response for the documentation, which again makes it available to XSS.The greatest threat to the system is for confidentiality, integrity, and availability.</Note>
    </Notes>
    <CVE>CVE-2021-3509</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ceph-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-base-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mds-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mon-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-osd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-radosgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-shell-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-top-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libradospp-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd1-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-cephfs-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rados-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rbd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rados-objclass-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-nbd-16.2.6.45+g8fda9838398-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-3509.html</URL>
        <Description>CVE-2021-3509</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186021</URL>
        <Description>SUSE Bug 1186021</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. In addition, the prior bug fix for CVE-2020-10753 did not account for the use of \r as a header separator, thus a new flaw has been created.</Note>
    </Notes>
    <CVE>CVE-2021-3524</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ceph-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-base-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mds-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mon-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-osd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-radosgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-shell-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-top-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libradospp-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd1-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-cephfs-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rados-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rbd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rados-objclass-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-nbd-16.2.6.45+g8fda9838398-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-3524.html</URL>
        <Description>CVE-2021-3524</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1185619</URL>
        <Description>SUSE Bug 1185619</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a denial of service. The greatest threat to the system is of availability.</Note>
    </Notes>
    <CVE>CVE-2021-3531</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ceph-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-base-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mds-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mon-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-osd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-radosgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephadm-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-shell-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-top-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libradospp-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd1-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw2-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-common-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-cephfs-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rados-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rbd-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rgw-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rados-objclass-devel-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-fuse-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-mirror-16.2.6.45+g8fda9838398-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-nbd-16.2.6.45+g8fda9838398-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-3531.html</URL>
        <Description>CVE-2021-3531</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186020</URL>
        <Description>SUSE Bug 1186020</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
