CVE-2016-8626
published 2018-07-31CVE-2016-8626: A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an authenticated attacker to launch a denial…
PriorityP432medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
2.31%
81.5th percentile
A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an authenticated attacker to launch a denial of service attack by sending null or specially crafted POST object requests.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ceph | < ceph 10.2.5-1 (bookworm) | ceph 10.2.5-1 (bookworm) |
| red_hat | ceph | — | — |
| red_hat | ceph | >= 0 < 10.2.5-1 | 10.2.5-1 |
| red_hat | ceph | >= 0 < 10.2.5-1 | 10.2.5-1 |
| red_hat | ceph | >= 0 < 10.2.5-1 | 10.2.5-1 |
| red_hat | ceph | >= 0 < 10.2.5-1 | 10.2.5-1 |
| redhat | ceph | < 0.94.3.9-8 | 0.94.3.9-8 |
| redhat | ceph | >= 0 < 0.80.11-0ubuntu1.14.04.3 | 0.80.11-0ubuntu1.14.04.3 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ceph vulnerabilities
vendor_ubuntu·2017-10-11·CVSS 6.5
CVE-2016-5009 [MEDIUM] Ceph vulnerabilities
Title: Ceph vulnerabilities
Summary: Several security issues were fixed in Ceph.
It was discovered that Ceph incorrectly handled the handle_command
function. A remote authenticated user could use this issue to cause Ceph to
crash, resulting in a denial of service. (CVE-2016-5009)
Rahul Aggarwal discovered that Ceph incorrectly handled the
authenticated-read ACL. A remote attacker could possibly use this issue to
list bucket contents via a URL. (CVE-2016-7031)
Diluga Salome discovered that Ceph incorrectly handled certain POST objects
with null conditions. A remote attacker could possibly use this issue to
cuase Ceph to crash, resulting in a denial of service. (CVE-2016-8626)
Yang Liu discovered that Ceph incorrectly handled invalid HTTP Origin
headers. A remote attacker could possibly
Red Hat
Ceph: RGW Denial of Service by sending null or specially crafted POST object requests
vendor_redhat·2016-10-20·CVSS 6.5
CVE-2016-8626 [MEDIUM] CWE-476 Ceph: RGW Denial of Service by sending null or specially crafted POST object requests
Ceph: RGW Denial of Service by sending null or specially crafted POST object requests
A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an authenticated attacker to launch a denial of service attack by sending null or specially crafted POST object requests.
A flaw was found in the way Ceph Object Gateway handles POST object requests. An authenticated attacker could launch a denial of service attack by sending null or specially crafted POST object requests.
Package: Ceph (OpenStack Foreman) - Not affected
Package: Ceph (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: Ceph (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Not affected
Debian
CVE-2016-8626: ceph - A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway ha...
vendor_debian·2016·CVSS 6.5
CVE-2016-8626 [MEDIUM] CVE-2016-8626: ceph - A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway ha...
A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an authenticated attacker to launch a denial of service attack by sending null or specially crafted POST object requests.
Scope: local
bookworm: resolved (fixed in 10.2.5-1)
bullseye: resolved (fixed in 10.2.5-1)
forky: resolved (fixed in 10.2.5-1)
sid: resolved (fixed in 10.2.5-1)
trixie: resolved (fixed in 10.2.5-1)
GHSA
GHSA-784r-h477-mqpc: A flaw was found in Red Hat Ceph before 0
ghsa_unreviewed·2022-05-13
CVE-2016-8626 [MEDIUM] CWE-20 GHSA-784r-h477-mqpc: A flaw was found in Red Hat Ceph before 0
A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an authenticated attacker to launch a denial of service attack by sending null or specially crafted POST object requests.
OSV
CVE-2016-8626: A flaw was found in Red Hat Ceph before 0
osv·2018-07-31·CVSS 6.5
CVE-2016-8626 [MEDIUM] CVE-2016-8626: A flaw was found in Red Hat Ceph before 0
A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an authenticated attacker to launch a denial of service attack by sending null or specially crafted POST object requests.
OSV
ceph vulnerabilities
osv·2017-10-11·CVSS 6.5
CVE-2016-5009 [MEDIUM] ceph vulnerabilities
ceph vulnerabilities
It was discovered that Ceph incorrectly handled the handle_command
function. A remote authenticated user could use this issue to cause Ceph to
crash, resulting in a denial of service. (CVE-2016-5009)
Rahul Aggarwal discovered that Ceph incorrectly handled the
authenticated-read ACL. A remote attacker could possibly use this issue to
list bucket contents via a URL. (CVE-2016-7031)
Diluga Salome discovered that Ceph incorrectly handled certain POST objects
with null conditions. A remote attacker could possibly use this issue to
cuase Ceph to crash, resulting in a denial of service. (CVE-2016-8626)
Yang Liu discovered that Ceph incorrectly handled invalid HTTP Origin
headers. A remote attacker could possibly use this issue to cuase Ceph to
crash, resulting in a denial
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2016-2815.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2816.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2847.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2848.htmlhttp://tracker.ceph.com/issues/17635http://www.securityfocus.com/bid/94488https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8626http://rhn.redhat.com/errata/RHSA-2016-2815.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2816.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2847.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2848.htmlhttp://tracker.ceph.com/issues/17635http://www.securityfocus.com/bid/94488https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8626
2018-07-31
Published