The Ceph Blog

Ceph blog stories provide high-level spotlights on our customers all over the world

May 13, 2021

v15.2.12 Octopus released

This is a hotfix release addressing a number of security issues and regressions. We recommend all users update to this release.


  • mgr/dashboard: fix base-href: revert it to previous approach (issue#50684, Avan Thakkar)

  • mgr/dashboard: fix cookie injection issue (CVE-2021-3509, Ernesto Puerta)

  • rgw: RGWSwiftWebsiteHandler::is_web_dir checks empty subdir_name (CVE-2021-3531, Felix Huettner)

  • rgw: sanitize \r in s3 CORSConfiguration’s ExposeHeader (CVE-2021-3524, Sergey Bobrov, Casey Bodley)