CVE-2016-9579: Input Validation
Published Aug 1, 2018
·Updated
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker could use this flaw to cause denial of service by sending a specially-crafted cross-origin HTTP request. Ceph branches 1.3.x and 2.x are affected.
Affected Software
12 affected components
redhat Ceph Storage=1.3
redhat Ceph Storage Mon=1.3
redhat Ceph Storage Mon=2
redhat Ceph Storage Osd=1.3
redhat Ceph Storage Osd=2
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Workstation=7.0
redhat Ceph Storage=2.0
Canonical Ubuntu Linux=16.04
redhat Enterprise Linux=7.0
Canonical Ubuntu Linux=14.04
Remediation
Patch Available
Event History
Aug 1, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this flaw?
The vulnerability ID is CVE-2016-9579.
2
What is the severity level of CVE-2016-9579?
The severity level of CVE-2016-9579 is high.
3
Which software is affected by CVE-2016-9579?
The software affected by CVE-2016-9579 includes Ceph Storage versions 1.3 and 2, Ceph Storage Mon 1.3 and 2, and Ceph Storage Osd 1.3 and 2.
4
How can an attacker exploit CVE-2016-9579?
An attacker can exploit CVE-2016-9579 by sending a specially-crafted cross-origin HTTP request.
5
Are Ubuntu Linux and Redhat Enterprise Linux vulnerable to CVE-2016-9579?
No, Ubuntu Linux and Redhat Enterprise Linux are not vulnerable to CVE-2016-9579.