PT-2016-7784 · Red Hat+1 · Ceph+1

Andrej Nemec

·

Publicado

2016-12-12

·

Atualizado

2023-02-12

·

CVE-2016-9579

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Ceph versions 1.3.x through 2.x
Description A flaw in Ceph Object Gateway's processing of cross-origin HTTP requests can cause a denial of service when the CORS policy allows origin on a bucket. This can be exploited by a remote unauthenticated attacker sending a specially-crafted cross-origin HTTP request.
Recommendations For versions 1.3.x and 2.x, update to a version that includes a fix for this issue to prevent denial of service attacks.

Exploit

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-9579
RHSA-2016:2954
RHSA-2016:2994
SUSE-SU-2017:1479-1
SUSE-SU-2017:3171-1
USN-3452-1

Produtos afetados

Ceph
Ubuntu