PT-2016-7784 · Red Hat+1 · Ceph+1
Andrej Nemec
·
Publicado
2016-12-12
·
Atualizado
2023-02-12
·
CVE-2016-9579
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Ceph versions 1.3.x through 2.x
Description
A flaw in Ceph Object Gateway's processing of cross-origin HTTP requests can cause a denial of service when the CORS policy allows origin on a bucket. This can be exploited by a remote unauthenticated attacker sending a specially-crafted cross-origin HTTP request.
Recommendations
For versions 1.3.x and 2.x, update to a version that includes a fix for this issue to prevent denial of service attacks.
Exploit
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ceph
Ubuntu