Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5245

Опубликовано: 18 авг. 2015
Источник: redhat
CVSS2: 5.5
EPSS Низкий

Описание

CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted bucket name.

A feature in Ceph Object Gateway (RGW) allows to return a specific HTTP header that contains the name of a bucket that was accessed. It was found that the returned HTTP headers were not sanitized. An unauthenticated attacker could use this flaw to craft HTTP headers in responses that would confuse the load balancer residing in front of RGW, potentially resulting in a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.2cephWill not fix
Red Hat Ceph Storage 1.3 for Red Hat Enterprise Linux 7babeltraceFixedRHSA-2015:206623.11.2015
Red Hat Ceph Storage 1.3 for Red Hat Enterprise Linux 7calamari-serverFixedRHSA-2015:206623.11.2015
Red Hat Ceph Storage 1.3 for Red Hat Enterprise Linux 7cephFixedRHSA-2015:206623.11.2015
Red Hat Ceph Storage 1.3 for Red Hat Enterprise Linux 7ceph-deployFixedRHSA-2015:206623.11.2015
Red Hat Ceph Storage 1.3 for Red Hat Enterprise Linux 7ceph-puppet-modulesFixedRHSA-2015:206623.11.2015
Red Hat Ceph Storage 1.3 for Red Hat Enterprise Linux 7facterFixedRHSA-2015:206623.11.2015
Red Hat Ceph Storage 1.3 for Red Hat Enterprise Linux 7foremanFixedRHSA-2015:206623.11.2015
Red Hat Ceph Storage 1.3 for Red Hat Enterprise Linux 7foreman-installerFixedRHSA-2015:206623.11.2015
Red Hat Ceph Storage 1.3 for Red Hat Enterprise Linux 7foreman-proxyFixedRHSA-2015:206623.11.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1261606Ceph: RGW returns requested bucket name raw in Bucket response header

EPSS

Процентиль: 58%
0.00361
Низкий

5.5 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted bucket name.

nvd
около 10 лет назад

CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted bucket name.

debian
около 10 лет назад

CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw o ...

github
больше 3 лет назад

CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted bucket name.

EPSS

Процентиль: 58%
0.00361
Низкий

5.5 Medium

CVSS2