CVE-2019-10222: High severity ceph vulnerability
Published Nov 8, 2019
·Updated
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.
Affected Software
5 affected components
ceph Ceph
redhat Ceph Storage=3.0
redhat Ceph Storage=3.3
Fedoraproject Fedora=30
Fedoraproject Fedora=31
Remediation
Patch Available
Event History
Nov 8, 2019
CVE Published
02:45 PM
Data Sourced
02:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-10222?
CVE-2019-10222 is a vulnerability in the Ceph RGW configuration with Beast as the front end handling client requests.
2
What is the severity of CVE-2019-10222?
CVE-2019-10222 has a severity level of 7.5 (high).
3
How does CVE-2019-10222 affect Ceph and Red Hat Ceph Storage?
CVE-2019-10222 affects Ceph and Red Hat Ceph Storage versions 3.0 and 3.3.
4
How can an unauthenticated attacker exploit CVE-2019-10222?
An unauthenticated attacker can crash the Ceph RGW server by sending valid HTTP headers and terminating the connection.
5
How can CVE-2019-10222 be fixed?
Apply the necessary updates or patches provided by the vendor to mitigate the vulnerability in Ceph RGW.