Msrc Azl3 Ceph 18.2.2-10 On Azure Linux 3.0 vulnerabilities

7 known vulnerabilities affecting msrc/azl3_ceph_18.2.2-10_on_azure_linux_3.0.

Total CVEs
7
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2MEDIUM2LOW1

Vulnerabilities

Page 1 of 1
CVE-2025-49844CRITICALCVSS 9.9PoC2025-10-14
CVE-2025-49844 [CRITICAL] CWE-416 Redis Lua Use-After-Free may lead to remote code execution Redis Lua Use-After-Free may lead to remote code execution FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries wi
msrc
CVE-2025-46819MEDIUMCVSS 6.3PoC2025-10-14
CVE-2025-46819 [MEDIUM] CWE-190 Redis is vulnerable to DoS via specially crafted LUA scripts Redis is vulnerable to DoS via specially crafted LUA scripts FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries
msrc
CVE-2025-57052CRITICALCVSS 9.82025-09-09
CVE-2025-57052 [CRITICAL] CWE-125 cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricte cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric
msrc
CVE-2025-9648HIGHCVSS 8.72025-09-09
CVE-2025-9648 [HIGH] CWE-158 Denial of Service in CivetWeb Denial of Service in CivetWeb FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to tran
msrc
CVE-2024-48916HIGHCVSS 8.12025-07-08
CVE-2024-48916 [HIGH] CWE-345 Ceph is vulnerable to authentication bypass through RadosGW Ceph is vulnerable to authentication bypass through RadosGW FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with
msrc
CVE-2023-26819LOWCVSS 2.92025-04-08
CVE-2023-26819 [LOW] CWE-440 cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}. cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected
msrc
CVE-2018-7159MEDIUMCVSS 5.32018-05-08
CVE-2018-7159 [MEDIUM] CWE-115 The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP spe The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not allow for spaces in the `Content-Length` value a
msrc