CVE-2015-5245

Ceph < 0.94.3 - CRLF Injection via Bucket Name

Title source: llm
STIX 2.1

Description

CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted bucket name.

References (3)

Core 3
Core References
Issue Tracking x_refsource_confirm
http://tracker.ceph.com/issues/12537
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2015:2512

Scores

EPSS 0.0191
EPSS Percentile 77.6%

Details

Status published
Products (1)
redhat/ceph < 0.94.3
Published Dec 03, 2015
Tracked Since Feb 18, 2026