CVE-2024-47866: RGW DoS attack with empty HTTP header in S3 object copy
Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument x-amz-copy-source to put an object and specifying an empty string as its content leads to the RGW daemon crashing, resulting in a DoS attack. As of time of publication, no known patched versions exist.
Other sources
Ceph RGW will crash if x-amz-copy-source is used to put an empty string as the object, resulting in impact to availability.
— Red Hat
RGW DoS attack with empty HTTP header in S3 object copy
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47866?
CVE-2024-47866 has a high severity rating as it allows for a Denial of Service attack due to the RGW daemon crashing.
How do I fix CVE-2024-47866?
To fix CVE-2024-47866, upgrade Ceph to version 19.2.4 or later, where the vulnerability has been addressed.
What versions of Ceph are affected by CVE-2024-47866?
CVE-2024-47866 affects Ceph versions up to and including 19.2.3.
What happens when the x-amz-copy-source argument is used with an empty string in CVE-2024-47866?
Using the x-amz-copy-source argument with an empty string in CVE-2024-47866 causes the RGW daemon to crash.
Is there a workaround for CVE-2024-47866?
Currently, the best approach for CVE-2024-47866 is to upgrade to a patched version, as no specific workaround is recommended.