A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ceph16Upgrade ceph | Aug 22, 2024 | Nov 8, 2019 |
| Centos_linux | — | Upgrade libcephfs-develUpgrade libcephfs2Upgrade ceph-baseUpgrade ceph-commonUpgrade librados-develUpgrade librgw-develUpgrade libradosstriper1Upgrade librgw2Upgrade ceph-radosgwUpgrade ceph-debuginfoUpgrade python-cephfsUpgrade ceph-mdsUpgrade ceph-fuseUpgrade ceph-selinuxUpgrade python-rgwUpgrade rbd-mirrorUpgrade librbd-devel | Mar 2, 2020 | Nov 8, 2019 |
| Debian | — | Upgrade ceph | Oct 25, 2023 | Nov 8, 2019 |
| Redhat_linux | — | Upgrade libcephfs2Upgrade ceph-radosgwUpgrade librgw-develUpgrade ceph-mdsUpgrade libcephfs-develUpgrade librgw2Upgrade librbd-develUpgrade ceph-commonUpgrade librados-develUpgrade libradosstriper1Upgrade python-rgwUpgrade rbd-mirrorUpgrade python-cephfsUpgrade ceph-selinuxUpgrade ceph-baseUpgrade ceph-fuseUpgrade ceph-debuginfo | Mar 2, 2020 | Nov 8, 2019 |
| Suse | — | Upgrade libradospp-develUpgrade python3-rgwUpgrade python3-rbdUpgrade librgw2Upgrade libcephfs-develUpgrade rbd-nbdUpgrade librgw-develUpgrade ceph-commonUpgrade python3-ceph-argparseUpgrade libcephfs2Upgrade librbd-develUpgrade python3-radosUpgrade rados-objclass-develUpgrade python3-ceph-commonUpgrade librados-develUpgrade python3-cephfsUpgrade librbd1Upgrade librados2 | Feb 4, 2022 | Aug 29, 2019 |
| Ubuntu | — | Upgrade radosgwUpgrade ceph | Aug 30, 2019 | Aug 29, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub