Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-3531

Опубликовано: 18 мая 2021
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a denial of service. The greatest threat to the system is of availability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:ceph:*:*:*:*:*:*:*:*
Версия до 14.2.21 (исключая)
cpe:2.3:a:redhat:ceph_storage:4.0:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

EPSS

Процентиль: 49%
0.00257
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-617

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 4 лет назад

A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a denial of service. The greatest threat to the system is of availability.

CVSS3: 5.3
redhat
больше 4 лет назад

A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a denial of service. The greatest threat to the system is of availability.

CVSS3: 5.3
debian
больше 4 лет назад

A flaw was found in the Red Hat Ceph Storage RGW in versions before 14 ...

CVSS3: 5.3
github
больше 3 лет назад

A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a denial of service. The greatest threat to the system is of availability.

CVSS3: 5.3
fstec
почти 5 лет назад

Уязвимость компонента RGW системы хранения данных Ceph, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 49%
0.00257
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-617