CVE-2021-3531: Input Validation

Published Apr 29, 2021
·
Updated

A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a denial of service. The greatest threat to the system is of availability.

Other sources

A flaw was found in the Red Hat Ceph Storage RGW. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a denial of service.

As an example consider the following curl command: curl https://<rgw-url>/swift/v1/AUTHa1c6e2f79c4b412f9e0335bc6120aeae/foo//<https://%3crgw-url%3e/swift/v1/AUTHa1c6e2f79c4b412f9e0335bc6120aeae/foo/>

the path before the bucket name (before "foo") must be valid for this to work. "foo" does not necessarily need to be a valid bucket name. If it is a valid bucket name it is irrelevant if the bucket itself is public or not. Additional query parameters in the URL still cause this issue (e.g. curl https://<rgw-url>/swift/v1/AUTHa1c6e2f79c4b412f9e0335bc6120aeae/foo//?abc<https://%3crgw-url%3e/swift/v1/AUTHa1c6e2f79c4b412f9e0335bc6120aeae/foo/?abc>)

Red Hat

Affected Software

6 affected componentsFixes available
redhat/ceph<14.2.21
14.2.21
redhat Ceph<14.2.21
redhat Ceph Storage=4.0
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Fedoraproject Fedora=34

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/ceph to a version that resolves this vulnerability.

    Fixed in 14.2.21
  2. Upgrade

    Upgrade Red Hat Ceph Storage RGW to a version that resolves this vulnerability.

    Fixed in 14.2.21
  3. Compensating control

    For swift URLs handled by RGW, avoid GET requests where the URL ends with two slashes (e.g., paths like /swift/v1/.../foo//). Also avoid cases where additional query parameters are present (e.g., /foo//?abc), as they can still trigger the issue.

Event History

May 18, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2021-3531?

The severity of CVE-2021-3531 is medium with a CVSS score of 5.3.

2

What is the impact of CVE-2021-3531?

CVE-2021-3531 can cause the Red Hat Ceph Storage RGW to crash, resulting in a denial of service.

3

Which versions of Red Hat Ceph Storage RGW are affected by CVE-2021-3531?

Versions before 14.2.21 of Red Hat Ceph Storage RGW are affected by CVE-2021-3531.

4

How can I fix CVE-2021-3531?

To fix CVE-2021-3531, update Red Hat Ceph Storage RGW to version 14.2.21 or later.

5

Where can I find more information about CVE-2021-3531?

You can find more information about CVE-2021-3531 on the following references: [https://%3crgw-url%3e/swift/v1/AUTH_a1c6e2f79c4b412f9e0335bc6120aeae/foo/](https://%3crgw-url%3e/swift/v1/AUTH_a1c6e2f79c4b412f9e0335bc6120aeae/foo/), [https://%3crgw-url%3e/swift/v1/AUTH_a1c6e2f79c4b412f9e0335bc6120aeae/foo/?abc](https://%3crgw-url%3e/swift/v1/AUTH_a1c6e2f79c4b412f9e0335bc6120aeae/foo/?abc), [https://github.com/ceph/ceph/commit/f44a8ae8aa27ecef69528db9aec220f12492810e](https://github.com/ceph/ceph/commit/f44a8ae8aa27ecef69528db9aec220f12492810e).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203