A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse this flaw by causing a remote denial of service by sending a specially crafted HTTP Content-Length header to the Ceph RADOS Gateway server.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ceph_storage | Redhat | 3.3 (including) | 3.3 (including) |
Red Hat Ceph Storage 3.3 | RedHat | ceph-2:12.2.12-84.el7cp | * |
Red Hat Ceph Storage 3.3 | RedHat | ceph-ansible-0:3.2.38-1.el7cp | * |
Red Hat Ceph Storage 3.3 | RedHat | cephmetrics-0:2.0.9-1.el7cp | * |
Red Hat Ceph Storage 3 for Ubuntu | RedHat | * | |
Ceph | Ubuntu | trusty | * |