NA

CVE-2022-3854

Published: 06/03/2023 Updated: 13/03/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ceph storage 3.0

redhat ceph storage 4.0

redhat ceph storage 5.0

Vendor Advisories

Debian Bug report logs - #1027151 ceph: CVE-2022-3854 Package: src:ceph; Maintainer for src:ceph is Ceph Packaging Team <team+ceph@trackerdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 28 Dec 2022 17:54:01 UTC Severity: important Tags: security, upstream Found in version ceph/16210+ds-3 ...
Description<!---->A flaw was found in Ceph, relating to the URL processing on RGW backends An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of serviceA flaw was found in Ceph, relating to the URL processing on RGW backends An attacker can exploit the URL processing by providing a null URL to c ...