Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-3854

Опубликовано: 06 мар. 2023
Источник: debian
EPSS Низкий

Описание

A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cephfixed16.2.10+ds-5package
cephnot-affectedbullseyepackage
cephnot-affectedbusterpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2139925

  • https://bugzilla.suse.com/show_bug.cgi?id=1205025

  • https://tracker.ceph.com/issues/55765

  • https://github.com/ceph/ceph/pull/47025

  • Introduced in https://github.com/ceph/ceph/commit/99f7c4aa1286edfea6961b92bb44bb8fe22bd599

EPSS

Процентиль: 25%
0.00088
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service.

CVSS3: 5
redhat
больше 3 лет назад

A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service.

CVSS3: 6.5
nvd
почти 3 года назад

A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service.

CVSS3: 6.5
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 6.5
github
почти 3 года назад

A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service.

EPSS

Процентиль: 25%
0.00088
Низкий