<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">ceph-16.2.6.463+g22e7612f9ad-1.1 on GA media</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2024:11652</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-06-17T21:45:33Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-06-17T21:45:33Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-06-17T21:45:33Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">ceph-16.2.6.463+g22e7612f9ad-1.1 on GA media</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">These are all security issues fixed in the ceph-16.2.6.463+g22e7612f9ad-1.1 package on the GA media of openSUSE Tumbleweed.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-Tumbleweed-2024-11652</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL/>
      <Description>E-Mail link for openSUSE-SU-2024:11652</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-25660/</URL>
      <Description>SUSE CVE CVE-2020-25660 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-25678/</URL>
      <Description>SUSE CVE CVE-2020-25678 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-27781/</URL>
      <Description>SUSE CVE CVE-2020-27781 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-27839/</URL>
      <Description>SUSE CVE CVE-2020-27839 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="ceph-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-16.2.6.463+g22e7612f9ad-1.1">ceph-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-base-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-base-16.2.6.463+g22e7612f9ad-1.1">ceph-base-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-common-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-common-16.2.6.463+g22e7612f9ad-1.1">ceph-common-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-fuse-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-fuse-16.2.6.463+g22e7612f9ad-1.1">ceph-fuse-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-grafana-dashboards-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-grafana-dashboards-16.2.6.463+g22e7612f9ad-1.1">ceph-grafana-dashboards-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-immutable-object-cache-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-immutable-object-cache-16.2.6.463+g22e7612f9ad-1.1">ceph-immutable-object-cache-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mds-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-mds-16.2.6.463+g22e7612f9ad-1.1">ceph-mds-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mgr-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-mgr-16.2.6.463+g22e7612f9ad-1.1">ceph-mgr-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mgr-cephadm-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-mgr-cephadm-16.2.6.463+g22e7612f9ad-1.1">ceph-mgr-cephadm-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mgr-dashboard-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-mgr-dashboard-16.2.6.463+g22e7612f9ad-1.1">ceph-mgr-dashboard-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mgr-diskprediction-local-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-mgr-diskprediction-local-16.2.6.463+g22e7612f9ad-1.1">ceph-mgr-diskprediction-local-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mgr-k8sevents-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-mgr-k8sevents-16.2.6.463+g22e7612f9ad-1.1">ceph-mgr-k8sevents-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mgr-modules-core-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-mgr-modules-core-16.2.6.463+g22e7612f9ad-1.1">ceph-mgr-modules-core-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mgr-rook-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-mgr-rook-16.2.6.463+g22e7612f9ad-1.1">ceph-mgr-rook-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-mon-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-mon-16.2.6.463+g22e7612f9ad-1.1">ceph-mon-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-osd-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-osd-16.2.6.463+g22e7612f9ad-1.1">ceph-osd-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-prometheus-alerts-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-prometheus-alerts-16.2.6.463+g22e7612f9ad-1.1">ceph-prometheus-alerts-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ceph-radosgw-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="ceph-radosgw-16.2.6.463+g22e7612f9ad-1.1">ceph-radosgw-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cephadm-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="cephadm-16.2.6.463+g22e7612f9ad-1.1">cephadm-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cephfs-mirror-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="cephfs-mirror-16.2.6.463+g22e7612f9ad-1.1">cephfs-mirror-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cephfs-shell-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="cephfs-shell-16.2.6.463+g22e7612f9ad-1.1">cephfs-shell-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cephfs-top-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="cephfs-top-16.2.6.463+g22e7612f9ad-1.1">cephfs-top-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcephfs-devel-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="libcephfs-devel-16.2.6.463+g22e7612f9ad-1.1">libcephfs-devel-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcephfs2-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="libcephfs2-16.2.6.463+g22e7612f9ad-1.1">libcephfs2-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcephsqlite-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="libcephsqlite-16.2.6.463+g22e7612f9ad-1.1">libcephsqlite-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcephsqlite-devel-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="libcephsqlite-devel-16.2.6.463+g22e7612f9ad-1.1">libcephsqlite-devel-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="librados-devel-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="librados-devel-16.2.6.463+g22e7612f9ad-1.1">librados-devel-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="librados2-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="librados2-16.2.6.463+g22e7612f9ad-1.1">librados2-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libradospp-devel-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="libradospp-devel-16.2.6.463+g22e7612f9ad-1.1">libradospp-devel-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="librbd-devel-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="librbd-devel-16.2.6.463+g22e7612f9ad-1.1">librbd-devel-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="librbd1-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="librbd1-16.2.6.463+g22e7612f9ad-1.1">librbd1-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="librgw-devel-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="librgw-devel-16.2.6.463+g22e7612f9ad-1.1">librgw-devel-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="librgw2-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="librgw2-16.2.6.463+g22e7612f9ad-1.1">librgw2-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-ceph-argparse-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="python3-ceph-argparse-16.2.6.463+g22e7612f9ad-1.1">python3-ceph-argparse-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-ceph-common-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="python3-ceph-common-16.2.6.463+g22e7612f9ad-1.1">python3-ceph-common-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-cephfs-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="python3-cephfs-16.2.6.463+g22e7612f9ad-1.1">python3-cephfs-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-rados-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="python3-rados-16.2.6.463+g22e7612f9ad-1.1">python3-rados-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-rbd-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="python3-rbd-16.2.6.463+g22e7612f9ad-1.1">python3-rbd-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-rgw-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="python3-rgw-16.2.6.463+g22e7612f9ad-1.1">python3-rgw-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rados-objclass-devel-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="rados-objclass-devel-16.2.6.463+g22e7612f9ad-1.1">rados-objclass-devel-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rbd-fuse-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="rbd-fuse-16.2.6.463+g22e7612f9ad-1.1">rbd-fuse-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rbd-mirror-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="rbd-mirror-16.2.6.463+g22e7612f9ad-1.1">rbd-mirror-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rbd-nbd-16.2.6.463+g22e7612f9ad-1.1">
      <FullProductName ProductID="rbd-nbd-16.2.6.463+g22e7612f9ad-1.1">rbd-nbd-16.2.6.463+g22e7612f9ad-1.1</FullProductName>
    </Branch>
    <Relationship ProductReference="ceph-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-16.2.6.463+g22e7612f9ad-1.1">ceph-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-base-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-base-16.2.6.463+g22e7612f9ad-1.1">ceph-base-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-common-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-common-16.2.6.463+g22e7612f9ad-1.1">ceph-common-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-fuse-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-fuse-16.2.6.463+g22e7612f9ad-1.1">ceph-fuse-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-grafana-dashboards-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.463+g22e7612f9ad-1.1">ceph-grafana-dashboards-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-immutable-object-cache-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.463+g22e7612f9ad-1.1">ceph-immutable-object-cache-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mds-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mds-16.2.6.463+g22e7612f9ad-1.1">ceph-mds-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mgr-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mgr-16.2.6.463+g22e7612f9ad-1.1">ceph-mgr-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mgr-cephadm-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.463+g22e7612f9ad-1.1">ceph-mgr-cephadm-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mgr-dashboard-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.463+g22e7612f9ad-1.1">ceph-mgr-dashboard-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mgr-diskprediction-local-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.463+g22e7612f9ad-1.1">ceph-mgr-diskprediction-local-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mgr-k8sevents-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.463+g22e7612f9ad-1.1">ceph-mgr-k8sevents-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mgr-modules-core-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.463+g22e7612f9ad-1.1">ceph-mgr-modules-core-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mgr-rook-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.463+g22e7612f9ad-1.1">ceph-mgr-rook-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-mon-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-mon-16.2.6.463+g22e7612f9ad-1.1">ceph-mon-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-osd-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-osd-16.2.6.463+g22e7612f9ad-1.1">ceph-osd-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-prometheus-alerts-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.463+g22e7612f9ad-1.1">ceph-prometheus-alerts-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="ceph-radosgw-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:ceph-radosgw-16.2.6.463+g22e7612f9ad-1.1">ceph-radosgw-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="cephadm-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:cephadm-16.2.6.463+g22e7612f9ad-1.1">cephadm-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="cephfs-mirror-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:cephfs-mirror-16.2.6.463+g22e7612f9ad-1.1">cephfs-mirror-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="cephfs-shell-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:cephfs-shell-16.2.6.463+g22e7612f9ad-1.1">cephfs-shell-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="cephfs-top-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:cephfs-top-16.2.6.463+g22e7612f9ad-1.1">cephfs-top-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcephfs-devel-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libcephfs-devel-16.2.6.463+g22e7612f9ad-1.1">libcephfs-devel-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcephfs2-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libcephfs2-16.2.6.463+g22e7612f9ad-1.1">libcephfs2-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcephsqlite-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libcephsqlite-16.2.6.463+g22e7612f9ad-1.1">libcephsqlite-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcephsqlite-devel-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.463+g22e7612f9ad-1.1">libcephsqlite-devel-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="librados-devel-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:librados-devel-16.2.6.463+g22e7612f9ad-1.1">librados-devel-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="librados2-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:librados2-16.2.6.463+g22e7612f9ad-1.1">librados2-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="libradospp-devel-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:libradospp-devel-16.2.6.463+g22e7612f9ad-1.1">libradospp-devel-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="librbd-devel-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:librbd-devel-16.2.6.463+g22e7612f9ad-1.1">librbd-devel-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="librbd1-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:librbd1-16.2.6.463+g22e7612f9ad-1.1">librbd1-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="librgw-devel-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:librgw-devel-16.2.6.463+g22e7612f9ad-1.1">librgw-devel-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="librgw2-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:librgw2-16.2.6.463+g22e7612f9ad-1.1">librgw2-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-ceph-argparse-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.463+g22e7612f9ad-1.1">python3-ceph-argparse-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-ceph-common-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:python3-ceph-common-16.2.6.463+g22e7612f9ad-1.1">python3-ceph-common-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-cephfs-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:python3-cephfs-16.2.6.463+g22e7612f9ad-1.1">python3-cephfs-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-rados-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:python3-rados-16.2.6.463+g22e7612f9ad-1.1">python3-rados-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-rbd-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:python3-rbd-16.2.6.463+g22e7612f9ad-1.1">python3-rbd-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-rgw-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:python3-rgw-16.2.6.463+g22e7612f9ad-1.1">python3-rgw-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="rados-objclass-devel-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:rados-objclass-devel-16.2.6.463+g22e7612f9ad-1.1">rados-objclass-devel-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="rbd-fuse-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:rbd-fuse-16.2.6.463+g22e7612f9ad-1.1">rbd-fuse-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="rbd-mirror-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:rbd-mirror-16.2.6.463+g22e7612f9ad-1.1">rbd-mirror-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="rbd-nbd-16.2.6.463+g22e7612f9ad-1.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:rbd-nbd-16.2.6.463+g22e7612f9ad-1.1">rbd-nbd-16.2.6.463+g22e7612f9ad-1.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph service via a packet sniffer and perform actions allowed by the Ceph service. This issue is a reintroduction of CVE-2018-1128, affecting the msgr2 protocol. The msgr 2 protocol is used for all communication except older clients that do not support the msgr2 protocol. The msgr1 protocol is not affected. The highest threat from this vulnerability is to confidentiality, integrity, and system availability.</Note>
    </Notes>
    <CVE>CVE-2020-25660</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ceph-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-base-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-common-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-fuse-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mds-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mon-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-osd-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-radosgw-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephadm-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-mirror-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-shell-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-top-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs2-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados2-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libradospp-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd1-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw2-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-common-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-cephfs-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rados-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rbd-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rgw-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rados-objclass-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-fuse-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-mirror-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-nbd-16.2.6.463+g22e7612f9ad-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-25660.html</URL>
        <Description>CVE-2020-25660</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1177843</URL>
        <Description>SUSE Bug 1177843</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.</Note>
    </Notes>
    <CVE>CVE-2020-25678</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ceph-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-base-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-common-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-fuse-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mds-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mon-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-osd-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-radosgw-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephadm-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-mirror-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-shell-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-top-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs2-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados2-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libradospp-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd1-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw2-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-common-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-cephfs-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rados-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rbd-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rgw-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rados-objclass-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-fuse-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-mirror-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-nbd-16.2.6.463+g22e7612f9ad-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-25678.html</URL>
        <Description>CVE-2020-25678</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178905</URL>
        <Description>SUSE Bug 1178905</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. This flaw affects Ceph versions prior to 14.2.16, 15.x prior to 15.2.8, and 16.x prior to 16.2.0.</Note>
    </Notes>
    <CVE>CVE-2020-27781</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ceph-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-base-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-common-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-fuse-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mds-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mon-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-osd-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-radosgw-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephadm-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-mirror-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-shell-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-top-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs2-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados2-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libradospp-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd1-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw2-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-common-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-cephfs-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rados-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rbd-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rgw-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rados-objclass-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-fuse-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-mirror-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-nbd-16.2.6.463+g22e7612f9ad-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-27781.html</URL>
        <Description>CVE-2020-27781</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179802</URL>
        <Description>SUSE Bug 1179802</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1180155</URL>
        <Description>SUSE Bug 1180155</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser's localStorage which is potentially vulnerable to attackers via XSS attacks. The highest threat from this vulnerability is to data confidentiality and integrity.</Note>
    </Notes>
    <CVE>CVE-2020-27839</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:ceph-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-base-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-common-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-fuse-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-grafana-dashboards-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-immutable-object-cache-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mds-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-cephadm-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-dashboard-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-diskprediction-local-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-k8sevents-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-modules-core-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mgr-rook-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-mon-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-osd-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-prometheus-alerts-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:ceph-radosgw-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephadm-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-mirror-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-shell-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:cephfs-top-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephfs2-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libcephsqlite-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librados2-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:libradospp-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librbd1-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:librgw2-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-argparse-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-ceph-common-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-cephfs-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rados-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rbd-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:python3-rgw-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rados-objclass-devel-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-fuse-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-mirror-16.2.6.463+g22e7612f9ad-1.1</ProductID>
        <ProductID>openSUSE Tumbleweed:rbd-nbd-16.2.6.463+g22e7612f9ad-1.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-27839.html</URL>
        <Description>CVE-2020-27839</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179997</URL>
        <Description>SUSE Bug 1179997</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
