CVE-2015-5245
Severity
4.3MEDIUM
EPSS
0.4%
top 41.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 3
Latest updateMay 17
Description
CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted bucket name.
CVSS vector
AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9
Affected Packages2 packages
🔴Vulnerability Details
3GHSAâ–¶
GHSA-782g-wgjp-wr8j: CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0↗2022-05-17
OSVâ–¶
CVE-2015-5245: CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0↗2015-12-03
CVEListâ–¶
CVE-2015-5245: CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0↗2015-12-03
📋Vendor Advisories
2💬Community
1Bugzilla
â–¶