v15.2.12 Octopus released

dgalloway

This is a hotfix release addressing a number of security issues and regressions. We recommend all users update to this release.

Changelog

  • mgr/dashboard: fix base-href: revert it to previous approach (issue#50684, Avan Thakkar)

  • mgr/dashboard: fix cookie injection issue (CVE-2021-3509, Ernesto Puerta)

  • rgw: RGWSwiftWebsiteHandler::is_web_dir checks empty subdir_name (CVE-2021-3531, Felix Huettner)

  • rgw: sanitize \r in s3 CORSConfiguration's ExposeHeader (CVE-2021-3524, Sergey Bobrov, Casey Bodley)