A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker could use this flaw to cause denial of service by sending a specially-crafted cross-origin HTTP request. Ceph branches 1.3.x and 2.x are affected.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ceph | Jul 30, 2024 | Aug 1, 2018 |
| Redhat_linux | — | Upgrade ceph-baseUpgrade python-radosUpgrade ceph-selinuxUpgrade librgw2-develUpgrade rbd-mirrorUpgrade python-cephfsUpgrade ceph-fuseUpgrade ceph-radosgwUpgrade librgw2Upgrade ceph-commonUpgrade ceph-mdsUpgrade ceph-debuginfoUpgrade python-rbdUpgrade libcephfs1-develUpgrade libcephfs1 | Dec 21, 2016 | Dec 15, 2016 |
| Suse | — | Upgrade libradosstriper1-debuginfoUpgrade ceph-radosgw-debuginfoUpgrade libcephfs1Upgrade python-rbdUpgrade rbd-nbd-debuginfoUpgrade librados-develUpgrade librgw-develUpgrade libradosstriper-develUpgrade ceph-baseUpgrade python-cephfs-debuginfoUpgrade ceph-base-debuginfoUpgrade ceph-mdsUpgrade ceph-monUpgrade librgw2Upgrade python-rbd-debuginfoUpgrade ceph-fuse-debuginfoUpgrade librgw2-debuginfoUpgrade rbd-fuseUpgrade librbd-develUpgrade python-cephfsUpgrade rbd-mirrorUpgrade ceph-mon-debuginfoUpgrade rbd-mirror-debuginfoUpgrade ceph-testUpgrade cephUpgrade ceph-fuseUpgrade librbd1Upgrade python-ceph-compatUpgrade python-rados-debuginfoUpgrade librbd1-debuginfoUpgrade ceph-resource-agentsUpgrade ceph-osdUpgrade ceph-commonUpgrade libcephfs-develUpgrade ceph-osd-debuginfoUpgrade libradosstriper1Upgrade librados2Upgrade ceph-radosgwUpgrade ceph-test-debuginfoUpgrade ceph-common-debuginfoUpgrade librados2-debuginfoUpgrade rbd-nbdUpgrade librados-devel-debuginfoUpgrade rbd-fuse-debuginfoUpgrade libcephfs1-debuginfoUpgrade ceph-mds-debuginfoUpgrade python-rados | Apr 5, 2017 | Dec 15, 2016 |
| Ubuntu | — | Upgrade ceph-commonUpgrade ceph | Oct 11, 2017 | Dec 15, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub