Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-46159

Опубликовано: 03 окт. 2023
Источник: redhat
CVSS3: 2.6
EPSS Низкий

Описание

IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service from RGW. IBM X-Force ID: 268906.

A flaw was found in Ceph. Certain misconfigurations of CORS rules in Ceph could result in a significantly large memory allocation. This issue can lead to RGW crashing and a denial of service from an authenticated user on the network.

Отчет

Red Hat Enterprise Linux does not ship RGW, only the associated client libraries. Hence, versions of Ceph shipped in RHEL are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 3cephNot affected
Red Hat Ceph Storage 4cephNot affected
Red Hat Enterprise Linux 8cephNot affected
Red Hat Enterprise Linux 9cephNot affected
Red Hat Openshift Container Storage 4cephNot affected
Red Hat Openshift Data Foundation 4cephNot affected
Red Hat OpenStack Platform 13 (Queens)cephNot affected
Red Hat Ceph Storage 5.3cephFixedRHSA-2024:074508.02.2024
Red Hat Ceph Storage 5.3ceph-ansibleFixedRHSA-2024:074508.02.2024
Red Hat Ceph Storage 5.3haproxyFixedRHSA-2024:074508.02.2024

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2215374ceph: RGW crash upon misconfigured CORS rule

EPSS

Процентиль: 7%
0.00026
Низкий

2.6 Low

CVSS3

Связанные уязвимости

CVSS3: 2.6
nvd
около 2 лет назад

IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service from RGW. IBM X-Force ID: 268906.

CVSS3: 2.6
github
около 2 лет назад

IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service from RGW. IBM X-Force ID: 268906.

EPSS

Процентиль: 7%
0.00026
Низкий

2.6 Low

CVSS3