CVE-2016-9579
published 2018-08-01CVE-2016-9579: A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote…
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
4.40%
90.2th percentile
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker could use this flaw to cause denial of service by sending a specially-crafted cross-origin HTTP request. Ceph branches 1.3.x and 2.x are affected.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ceph | < ceph 10.2.5-2 (bookworm) | ceph 10.2.5-2 (bookworm) |
| red_hat | ceph | — | — |
| red_hat | ceph | >= 0 < 10.2.5-2 | 10.2.5-2 |
| red_hat | ceph | >= 0 < 10.2.5-2 | 10.2.5-2 |
| red_hat | ceph | >= 0 < 10.2.5-2 | 10.2.5-2 |
| red_hat | ceph | >= 0 < 10.2.5-2 | 10.2.5-2 |
| redhat | ceph | >= 0 < 0.80.11-0ubuntu1.14.04.3 | 0.80.11-0ubuntu1.14.04.3 |
| redhat | ceph_storage | — | — |
| redhat | ceph_storage | — | — |
| redhat | ceph_storage_mon | — | — |
| redhat | ceph_storage_mon | — | — |
| redhat | ceph_storage_osd | — | — |
| redhat | ceph_storage_osd | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ceph vulnerabilities
vendor_ubuntu·2017-10-11·CVSS 6.5
CVE-2016-5009 [MEDIUM] Ceph vulnerabilities
Title: Ceph vulnerabilities
Summary: Several security issues were fixed in Ceph.
It was discovered that Ceph incorrectly handled the handle_command
function. A remote authenticated user could use this issue to cause Ceph to
crash, resulting in a denial of service. (CVE-2016-5009)
Rahul Aggarwal discovered that Ceph incorrectly handled the
authenticated-read ACL. A remote attacker could possibly use this issue to
list bucket contents via a URL. (CVE-2016-7031)
Diluga Salome discovered that Ceph incorrectly handled certain POST objects
with null conditions. A remote attacker could possibly use this issue to
cuase Ceph to crash, resulting in a denial of service. (CVE-2016-8626)
Yang Liu discovered that Ceph incorrectly handled invalid HTTP Origin
headers. A remote attacker could possibly
Red Hat
ceph: Object Gateway server DoS by sending invalid cross-origin HTTP request
vendor_redhat·2016-12-08·CVSS 6.5
CVE-2016-9579 [MEDIUM] CWE-20 ceph: Object Gateway server DoS by sending invalid cross-origin HTTP request
ceph: Object Gateway server DoS by sending invalid cross-origin HTTP request
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker could use this flaw to cause denial of service by sending a specially-crafted cross-origin HTTP request. Ceph branches 1.3.x and 2.x are affected.
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker could use this flaw to cause denial of service by sending a specially-crafted cross-origin HTTP request.
Package: ceph (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: ceph (Red Ha
Debian
CVE-2016-9579: ceph - A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP ...
vendor_debian·2016·CVSS 6.5
CVE-2016-9579 [MEDIUM] CVE-2016-9579: ceph - A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP ...
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker could use this flaw to cause denial of service by sending a specially-crafted cross-origin HTTP request. Ceph branches 1.3.x and 2.x are affected.
Scope: local
bookworm: resolved (fixed in 10.2.5-2)
bullseye: resolved (fixed in 10.2.5-2)
forky: resolved (fixed in 10.2.5-2)
sid: resolved (fixed in 10.2.5-2)
trixie: resolved (fixed in 10.2.5-2)
GHSA
GHSA-2594-xrq4-4jm3: A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket
ghsa_unreviewed·2022-05-13
CVE-2016-9579 [HIGH] CWE-20 GHSA-2594-xrq4-4jm3: A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker could use this flaw to cause denial of service by sending a specially-crafted cross-origin HTTP request. Ceph branches 1.3.x and 2.x are affected.
OSV
CVE-2016-9579: A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket
osv·2018-08-01·CVSS 7.5
CVE-2016-9579 [HIGH] CVE-2016-9579: A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker could use this flaw to cause denial of service by sending a specially-crafted cross-origin HTTP request. Ceph branches 1.3.x and 2.x are affected.
OSV
ceph vulnerabilities
osv·2017-10-11·CVSS 6.5
CVE-2016-5009 [MEDIUM] ceph vulnerabilities
ceph vulnerabilities
It was discovered that Ceph incorrectly handled the handle_command
function. A remote authenticated user could use this issue to cause Ceph to
crash, resulting in a denial of service. (CVE-2016-5009)
Rahul Aggarwal discovered that Ceph incorrectly handled the
authenticated-read ACL. A remote attacker could possibly use this issue to
list bucket contents via a URL. (CVE-2016-7031)
Diluga Salome discovered that Ceph incorrectly handled certain POST objects
with null conditions. A remote attacker could possibly use this issue to
cuase Ceph to crash, resulting in a denial of service. (CVE-2016-8626)
Yang Liu discovered that Ceph incorrectly handled invalid HTTP Origin
headers. A remote attacker could possibly use this issue to cuase Ceph to
crash, resulting in a denial
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9579 ceph: Object Gateway server DoS by sending invalid cross-origin HTTP request
bugzilla·2016-12-09·CVSS 6.5
CVE-2016-9579 [MEDIUM] CVE-2016-9579 ceph: Object Gateway server DoS by sending invalid cross-origin HTTP request
CVE-2016-9579 ceph: Object Gateway server DoS by sending invalid cross-origin HTTP request
An anonymous user can provoke an abort() of the RGW server by sending a request with an invalid HTTP Origin header, against buckets with CORS AllowedOrigin rules. The abort() is caused by an unhandled out-of-range exception matching the header with the supplied Origin header value.
Product bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1403003
Upstream bug:
http://tracker.ceph.com/issues/18187
Discussion:
Created ceph tracking bugs for this issue:
Affects: fedora-all [bug 1403246]
Affects: epel-all [bug 1403247]
---
Workaround:
1. By default system will use /etc/init.d/ceph-radosgw
stop this service by
~]# /etc/init.d/ceph-radosgw stop
2. Create systemd service, change command line par
Bugzilla
CVE-2016-9579 ceph: RGW server DoS via request with invalid HTTP Origin header [fedora-all]
bugzilla·2016-12-09·CVSS 6.5
CVE-2016-9579 [MEDIUM] CVE-2016-9579 ceph: RGW server DoS via request with invalid HTTP Origin header [fedora-all]
CVE-2016-9579 ceph: RGW server DoS via request with invalid HTTP Origin header [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2016-9579 ceph: RGW server DoS via request with invalid HTTP Origin header [epel-all]
bugzilla·2016-12-09·CVSS 6.5
CVE-2016-9579 [MEDIUM] CVE-2016-9579 ceph: RGW server DoS via request with invalid HTTP Origin header [epel-all]
CVE-2016-9579 ceph: RGW server DoS via request with invalid HTTP Origin header [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
http://rhn.redhat.com/errata/RHSA-2016-2954.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2956.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2994.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2995.htmlhttp://tracker.ceph.com/issues/18187http://www.securityfocus.com/bid/94936https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9579http://rhn.redhat.com/errata/RHSA-2016-2954.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2956.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2994.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2995.htmlhttp://tracker.ceph.com/issues/18187http://www.securityfocus.com/bid/94936https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9579
2018-08-01
Published