CVE-2019-10222
HIGHCeph - Unauthenticated Denial of Service via HTTP Connection Termination
Title source: llmDescription
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_misc
https://tracker.ceph.com/issues/40018
Issue Tracking, Mitigation, Patch, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10222
Scores
CVSS v3
7.5
EPSS
0.0180
EPSS Percentile
83.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-755
Status
published
Products (5)
ceph/ceph
fedoraproject/fedora
30
fedoraproject/fedora
31
redhat/ceph_storage
3.0
redhat/ceph_storage
3.3
Published
Nov 08, 2019
Tracked Since
Feb 18, 2026