Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-47866

Опубликовано: 12 нояб. 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument x-amz-copy-source to put an object and specifying an empty string as its content leads to the RGW daemon crashing, resulting in a DoS attack. As of time of publication, no known patched versions exist.

РелизСтатусПримечание
devel

needed

esm-infra-legacy/trusty

needed

esm-infra/bionic

needed

esm-infra/focal

needed

esm-infra/xenial

needed

jammy

needed

noble

needed

plucky

ignored

end of life, was needed
questing

needed

upstream

needs-triage

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put an object and specifying an empty string as its content leads to the RGW daemon crashing, resulting in a DoS attack. As of time of publication, no known patched versions exist.

CVSS3: 7.5
msrc
3 месяца назад

RGW DoS attack with empty HTTP header in S3 object copy

CVSS3: 7.5
debian
3 месяца назад

Ceph is a distributed object, block, and file storage platform. In ver ...

7.5 High

CVSS3