PT-2022-6797 · Ceph+4 · Ceph+4

Sage Mctaggart

·

Published

2022-05-25

·

Updated

2023-05-09

·

CVE-2022-3854

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Ceph (affected versions not specified)
Description A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Weakness Enumeration

Related Identifiers

AZL-38998
AZL-39496
BDU:2023-04791
CVE-2022-3854
OPENSUSE-SU-2024:12662-1
SUSE-SU-2023:1580-1
SUSE-SU-2023:1581-1
SUSE-SU-2023:1581-2
SUSE-SU-2023:1584-1
USN-6063-1

Affected Products

Astra Linux
Ceph
Linuxmint
Suse
Ubuntu