Wind River Support Network

HomeDefectsLIN7-11624
Fixed

LIN7-11624 : Security Advisory - ceph - CVE-2019-10222

Created: Nov 14, 2019    Updated: Apr 21, 2020
Resolved Date: Apr 21, 2020
Found In Version: 7.0.0.1
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Userspace

Description

A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.

CREATE(Triage):(User=admin) [CVE-2019-10222|https://nvd.nist.gov/vuln/detail/CVE-2019-10222]
Live chat
Online