A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust file descriptors for ceph-radosgw service resulting in a remote denial of service.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade python3-ceph-argparseUpgrade libcephfs2Upgrade librgw-develUpgrade librgw2Upgrade python3-ceph-commonUpgrade python3-cephfsUpgrade python3-rgwUpgrade python3-rbdUpgrade libradospp-develUpgrade librbd1Upgrade librbd-develUpgrade librados2Upgrade rbd-nbdUpgrade ceph-commonUpgrade libcephfs-develUpgrade librados-develUpgrade rados-objclass-develUpgrade python3-rados | Feb 4, 2022 | Mar 27, 2019 |
| Ubuntu | — | Upgrade cephUpgrade ceph-common | Jun 25, 2019 | Mar 27, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub