cbcvebase.
CVE-2022-3854
published 2023-03-06

CVE-2022-3854: A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW…

PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.56%
44.3th percentile
A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianceph< ceph 16.2.10+ds-5 (bookworm)ceph 16.2.10+ds-5 (bookworm)
msrcazl3_ceph_16.2.10-3_on_azure_linux_3.0
msrcazl3_ceph_18.2.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_ceph_16.2.10-7_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
redhatceph_storage
redhatceph_storage
redhatceph_storage
redhatceph_storage
redhatceph_storage>= 0 < 16.2.10+ds-516.2.10+ds-5
redhatceph_storage>= 0 < 16.2.10+ds-516.2.10+ds-5
redhatceph_storage>= 0 < 16.2.10+ds-516.2.10+ds-5
redhatceph_storage>= 0 < 12.2.13-0ubuntu0.18.04.1112.2.13-0ubuntu0.18.04.11
redhatceph_storage>= 0 < 15.2.17-0ubuntu0.20.04.315.2.17-0ubuntu0.20.04.3
redhatceph_storage>= 0 < 17.2.5-0ubuntu0.22.04.317.2.5-0ubuntu0.22.04.3

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.