6.5
CVSSv3

CVE-2016-8626

Published: 31/07/2018 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C

Vulnerability Summary

A flaw was found in Red Hat Ceph prior to 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an authenticated malicious user to launch a denial of service attack by sending null or specially crafted POST object requests.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ceph

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

Vendor Advisories

Several security issues were fixed in Ceph ...
Synopsis Moderate: Red Hat Ceph Storage 13 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat Ceph Storage 13 This erratum is applicable for Red Hat Ceph Storage that runs on Red Hat Enterprise Linux 7Red Hat Product Security ...
Synopsis Moderate: Red Hat Ceph Storage security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat Ceph Storage 21 that fix one security issue, multiple bugs, and add various enhancements This erratum is applicable for Red Hat Ceph Stor ...
Synopsis Moderate: Red Hat Ceph Storage security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat Ceph Storage 21 that fix one security issue, multiple bugs, and add various enhancements This erratum is applicable for Red Hat Ceph Stor ...
Synopsis Moderate: Red Hat Ceph Storage 13 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat Ceph Storage 13 This erratum is applicable for Red Hat Ceph Storage that runs on Ubuntu 1404Red Hat Product Security has rated this ...
Debian Bug report logs - #849048 ceph: CVE-2016-9579 Package: src:ceph; Maintainer for src:ceph is Ceph Maintainers <ceph-maintainers@listscephcom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 22 Dec 2016 05:51:02 UTC Severity: important Tags: security, upstream Found in versions ceph/08011- ...
Debian Bug report logs - #844200 ceph: CVE-2016-8626: RGW Denial of Service by sending POST object with null conditions Package: src:ceph; Maintainer for src:ceph is Ceph Maintainers <ceph-maintainers@listscephcom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 13 Nov 2016 10:12:02 UTC Severity: ...
Debian Bug report logs - #829661 ceph: CVE-2016-5009: Ceph monitor crash: mon_command crashes ceph monitors on receiving empty prefix Package: src:ceph; Maintainer for src:ceph is Ceph Maintainers <ceph-maintainers@listscephcom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 5 Jul 2016 06:12:11 U ...
Debian Bug report logs - #838026 ceph: CVE-2016-7031: rgw: Anonymous user is able to read bucket with authenticated read ACL Package: src:ceph; Maintainer for src:ceph is Ceph Maintainers <ceph-maintainers@listscephcom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 16 Sep 2016 15:15:01 UTC Sever ...
A flaw was found in the way Ceph Object Gateway handles POST object requests An authenticated attacker could launch a denial of service attack by sending null or specially crafted POST object requests ...