First published: Mon Dec 23 2019(Updated: )
A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse this flaw by causing a remote denial of service by sending a specially crafted HTTP Content-Length header to the Ceph RADOS Gateway server.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Ceph Storage | =3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19337 has a medium severity level due to its capability to cause a denial of service.
To fix CVE-2019-19337, upgrade Red Hat Ceph Storage to a version that addresses this flaw.
CVE-2019-19337 affects users of Red Hat Ceph Storage version 3.3.
CVE-2019-19337 allows an authenticated attacker to initiate a remote denial of service.
CVE-2019-19337 impacts the Ceph RADOS Gateway daemon handling S3 requests.