← Back

CVE-2019-10222

nvd nist
Published: Nov 8, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.

Affected (5)

1 product
Ceph
1 product
Ceph Storage
1 product
Fedora
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 3.0
Version 3.3
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 30
Version 31

References (6)

Source: secalert@redhat.com
Issue TrackingMitigationPatchVendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMitigationPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.