A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade cephUpgrade ceph16 | Aug 22, 2024 | Nov 8, 2019 |
| Centos_linux | — | Upgrade librgw-develUpgrade ceph-baseUpgrade libcephfs-develUpgrade librados-develUpgrade ceph-commonUpgrade libcephfs2Upgrade ceph-selinuxUpgrade rbd-mirrorUpgrade python-rgwUpgrade ceph-radosgwUpgrade ceph-fuseUpgrade python-cephfsUpgrade ceph-mdsUpgrade libradosstriper1Upgrade librbd-develUpgrade ceph-debuginfoUpgrade librgw2 | Mar 2, 2020 | Nov 8, 2019 |
| Debian | — | Upgrade ceph | Oct 25, 2023 | Nov 8, 2019 |
| Redhat_linux | — | Upgrade librgw2Upgrade libcephfs-develUpgrade librbd-develUpgrade ceph-radosgwUpgrade ceph-commonUpgrade librados-develUpgrade libcephfs2Upgrade ceph-mdsUpgrade librgw-develUpgrade ceph-debuginfoUpgrade python-rgwUpgrade python-cephfsUpgrade ceph-fuseUpgrade rbd-mirrorUpgrade ceph-selinuxUpgrade ceph-baseUpgrade libradosstriper1 | Mar 2, 2020 | Nov 8, 2019 |
| Suse | — | Upgrade python3-rbdUpgrade python3-rgwUpgrade libradospp-develUpgrade libcephfs-develUpgrade librados2Upgrade python3-ceph-commonUpgrade librgw-develUpgrade libcephfs2Upgrade librbd-develUpgrade librgw2Upgrade librados-develUpgrade python3-cephfsUpgrade rbd-nbdUpgrade librbd1Upgrade rados-objclass-develUpgrade python3-ceph-argparseUpgrade ceph-commonUpgrade python3-rados | Feb 4, 2022 | Aug 29, 2019 |
| Ubuntu | — | Upgrade radosgwUpgrade ceph | Aug 30, 2019 | Aug 29, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub