A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade cephUpgrade ceph16 | Aug 22, 2024 | Nov 8, 2019 |
| Centos_linux | — | Upgrade librgw-develUpgrade librados-develUpgrade libcephfs2Upgrade ceph-baseUpgrade ceph-commonUpgrade libcephfs-develUpgrade ceph-selinuxUpgrade rbd-mirrorUpgrade librbd-develUpgrade ceph-mdsUpgrade ceph-debuginfoUpgrade ceph-fuseUpgrade librgw2Upgrade python-cephfsUpgrade ceph-radosgwUpgrade libradosstriper1Upgrade python-rgw | Mar 2, 2020 | Nov 8, 2019 |
| Debian | — | Upgrade ceph | Oct 25, 2023 | Nov 8, 2019 |
| Redhat_linux | — | Upgrade ceph-fuseUpgrade ceph-selinuxUpgrade libradosstriper1Upgrade ceph-debuginfoUpgrade python-rgwUpgrade rbd-mirrorUpgrade python-cephfsUpgrade ceph-baseUpgrade libcephfs2Upgrade librbd-develUpgrade librados-develUpgrade ceph-radosgwUpgrade librgw-develUpgrade librgw2Upgrade ceph-mdsUpgrade libcephfs-develUpgrade ceph-common | Mar 2, 2020 | Nov 8, 2019 |
| Suse | — | Upgrade python3-rbdUpgrade libradospp-develUpgrade python3-rgwUpgrade rbd-nbdUpgrade librgw-develUpgrade python3-cephfsUpgrade librbd-develUpgrade rados-objclass-develUpgrade python3-radosUpgrade ceph-commonUpgrade libcephfs-develUpgrade librbd1Upgrade librados2Upgrade python3-ceph-commonUpgrade librados-develUpgrade librgw2Upgrade python3-ceph-argparseUpgrade libcephfs2 | Feb 4, 2022 | Aug 29, 2019 |
| Ubuntu | — | Upgrade cephUpgrade radosgw | Aug 30, 2019 | Aug 29, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub