Vulnerabilities
Vulnerable Software
Redhat:  >> Ceph  >> 12.1.2  Security Vulnerabilities
In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service.
CVSS Score
7.5
EPSS Score
0.007
Published
2018-03-19
RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an invalid profile to the admin API, related to rgw/rgw_iam_policy.cc, rgw/rgw_basic_types.h, and rgw/rgw_iam_types.h.
CVSS Score
6.5
EPSS Score
0.004
Published
2017-12-20


Contact Us

Shodan ® - All rights reserved