CVE-2019-10222
published 2019-11-08CVE-2019-10222: A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.61%
90.7th percentile
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ceph | < ceph 14.2.4-1 (bookworm) | ceph 14.2.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| redhat | ceph_storage | — | — |
| redhat | ceph_storage | — | — |
| the_ceph_project | ceph | — | — |
| the_ceph_project | ceph | >= 0 < 14.2.4-1 | 14.2.4-1 |
| the_ceph_project | ceph | >= 0 < 14.2.4-1 | 14.2.4-1 |
| the_ceph_project | ceph | >= 0 < 14.2.4-1 | 14.2.4-1 |
| the_ceph_project | ceph | >= 0 < 14.2.4-1 | 14.2.4-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ceph vulnerability
vendor_ubuntu·2019-08-29
CVE-2019-10222 Ceph vulnerability
Title: Ceph vulnerability
Summary: Ceph could be made to crash if it received specially crafted network
traffic.
Abhishek Lekshmanan discovered that the RADOS gateway implementation in
Ceph did not handle client disconnects properly in some situations. A
remote attacker could use this to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ceph: Unauthenticated clients can crash ceph RGW configured with beast as frontend
vendor_redhat·2019-08-28·CVSS 7.5
CVE-2019-10222 [HIGH] CWE-755 ceph: Unauthenticated clients can crash ceph RGW configured with beast as frontend
ceph: Unauthenticated clients can crash ceph RGW configured with beast as frontend
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.
Statement: Red Hat OpenStack Platform 13 included some Ceph components at release for in order to support ppc64le. The version provided in the O
Debian
CVE-2019-10222: ceph - A flaw was found in the Ceph RGW configuration with Beast as the front end handl...
vendor_debian·2019·CVSS 7.5
CVE-2019-10222 [HIGH] CVE-2019-10222: ceph - A flaw was found in the Ceph RGW configuration with Beast as the front end handl...
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.
Scope: local
bookworm: resolved (fixed in 14.2.4-1)
bullseye: resolved (fixed in 14.2.4-1)
forky: resolved (fixed in 14.2.4-1)
sid: resolved (fixed in 14.2.4-1)
trixie: resolved (fixed in 14.2.4-1)
GHSA
GHSA-vr4v-h7xq-hwc6: A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests
ghsa_unreviewed·2022-05-24
CVE-2019-10222 [MEDIUM] CWE-755 GHSA-vr4v-h7xq-hwc6: A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.
OSV
CVE-2019-10222: A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests
osv·2019-11-08·CVSS 7.5
CVE-2019-10222 [HIGH] CVE-2019-10222: A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10222 ceph: Unauthenticated clients can crash ceph RGW configured with beast as frontend [fedora-all]
bugzilla·2019-08-28·CVSS 7.5
CVE-2019-10222 [HIGH] CVE-2019-10222 ceph: Unauthenticated clients can crash ceph RGW configured with beast as frontend [fedora-all]
CVE-2019-10222 ceph: Unauthenticated clients can crash ceph RGW configured with beast as frontend [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
Bugzilla
CVE-2019-10222 ceph: Unauthenticated clients can crash ceph RGW configured with beast as frontend
bugzilla·2019-08-09·CVSS 7.5
CVE-2019-10222 [HIGH] CVE-2019-10222 ceph: Unauthenticated clients can crash ceph RGW configured with beast as frontend
CVE-2019-10222 ceph: Unauthenticated clients can crash ceph RGW configured with beast as frontend
A flaw was found in ceph. Any single unauthenticated client can crash RGW if valid HTTP headers are sent and the connection is terminated.
References:
https://tracker.ceph.com/issues/40018
Discussion:
Statement:
Red Hat OpenStack Platform 13 included some Ceph components at release for in order to support ppc64le. The version provided in the OpenStack repositories is outdated and customers are expected to be using versions provided in Ceph repositories now. Additionally, only the client side and libraries were included which are not affected by this vulnerability.
---
External References:
https://tracker.ceph.com/issues/40018
---
Acknowledgments:
Name: Abhishek Lekshmanan (SUSE Sof
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10222https://lists.debian.org/debian-lts-announce/2023/10/msg00034.htmlhttps://tracker.ceph.com/issues/40018https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10222https://lists.debian.org/debian-lts-announce/2023/10/msg00034.htmlhttps://tracker.ceph.com/issues/40018
2019-11-08
Published