Описание
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker could use this flaw to cause denial of service by sending a specially-crafted cross-origin HTTP request. Ceph branches 1.3.x and 2.x are affected.
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker could use this flaw to cause denial of service by sending a specially-crafted cross-origin HTTP request.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | ceph | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | ceph | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer | ceph | Not affected | ||
| Red Hat OpenStack Platform 10 (Newton) | puppet-ceph | Not affected | ||
| Red Hat Ceph Storage 1.3 for Red Hat Enterprise Linux 7 | ceph | Fixed | RHSA-2016:2994 | 21.12.2016 |
| Red Hat Ceph Storage 1.3 for Ubuntu | Fixed | RHSA-2016:2995 | 21.12.2016 | |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | ceph | Fixed | RHSA-2016:2954 | 15.12.2016 |
| Red Hat Ceph Storage 2 for Ubuntu | Fixed | RHSA-2016:2956 | 15.12.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
5 Medium
CVSS2
Связанные уязвимости
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker could use this flaw to cause denial of service by sending a specially-crafted cross-origin HTTP request. Ceph branches 1.3.x and 2.x are affected.
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker could use this flaw to cause denial of service by sending a specially-crafted cross-origin HTTP request. Ceph branches 1.3.x and 2.x are affected.
A flaw was found in the way Ceph Object Gateway would process cross-or ...
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker could use this flaw to cause denial of service by sending a specially-crafted cross-origin HTTP request. Ceph branches 1.3.x and 2.x are affected.
EPSS
6.5 Medium
CVSS3
5 Medium
CVSS2