CVE-2019-19337: Input Validation
Published Dec 23, 2019
·Updated
A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse this flaw by causing a remote denial of service by sending a specially crafted HTTP Content-Length header to the Ceph RADOS Gateway server.
Affected Software
1 affected component
redhat Ceph Storage=3.3
Event History
Dec 23, 2019
CVE Published
via MITRE·04:18 PM
Data Sourced
via MITRE·04:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-19337?
CVE-2019-19337 has a medium severity level due to its capability to cause a denial of service.
2
How do I fix CVE-2019-19337?
To fix CVE-2019-19337, upgrade Red Hat Ceph Storage to a version that addresses this flaw.
3
Who is affected by CVE-2019-19337?
CVE-2019-19337 affects users of Red Hat Ceph Storage version 3.3.
4
What type of attack does CVE-2019-19337 allow?
CVE-2019-19337 allows an authenticated attacker to initiate a remote denial of service.
5
What component of Red Hat Ceph Storage is impacted by CVE-2019-19337?
CVE-2019-19337 impacts the Ceph RADOS Gateway daemon handling S3 requests.