A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse this flaw by causing a remote denial of service by sending a specially crafted HTTP Content-Length header to the Ceph RADOS Gateway server.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade ceph-baseUpgrade libcephfs2Upgrade python-cephfsUpgrade librgw-develUpgrade librados-develUpgrade ceph-selinuxUpgrade rbd-mirrorUpgrade cephmetrics-ansibleUpgrade ceph-radosgwUpgrade ceph-commonUpgrade librbd-develUpgrade libcephfs-develUpgrade ceph-ansibleUpgrade ceph-debuginfoUpgrade librgw2Upgrade ceph-mdsUpgrade python-rgwUpgrade libradosstriper1Upgrade ceph-fuse | Mar 2, 2020 | Dec 23, 2019 |
| Redhat_linux | — | Upgrade cephmetrics-ansibleUpgrade rbd-mirrorUpgrade python-cephfsUpgrade ceph-debuginfoUpgrade ceph-radosgwUpgrade librados-develUpgrade librgw-develUpgrade libcephfs-develUpgrade ceph-commonUpgrade libcephfs2Upgrade ceph-fuseUpgrade librgw2Upgrade python-rgwUpgrade libradosstriper1Upgrade ceph-ansibleUpgrade ceph-mdsUpgrade ceph-baseUpgrade ceph-selinuxUpgrade librbd-devel | Mar 2, 2020 | Dec 23, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub