PT-2016-7784 · Red Hat+1 · Ceph+1

Andrej Nemec

·

Published

2016-12-12

·

Updated

2023-02-12

·

CVE-2016-9579

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Ceph versions 1.3.x through 2.x
Description A flaw in Ceph Object Gateway's processing of cross-origin HTTP requests can cause a denial of service when the CORS policy allows origin on a bucket. This can be exploited by a remote unauthenticated attacker sending a specially-crafted cross-origin HTTP request.
Recommendations For versions 1.3.x and 2.x, update to a version that includes a fix for this issue to prevent denial of service attacks.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-9579
RHSA-2016:2954
RHSA-2016:2994
SUSE-SU-2017:1479-1
SUSE-SU-2017:3171-1
USN-3452-1

Affected Products

Ceph
Ubuntu