CVE-2019-10222

HIGH

Ceph - Unauthenticated Denial of Service via HTTP Connection Termination

Title source: llm
STIX 2.1

Description

A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_misc
https://tracker.ceph.com/issues/40018
Issue Tracking, Mitigation, Patch, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10222

Scores

CVSS v3 7.5
EPSS 0.0180
EPSS Percentile 83.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-755
Status published
Products (5)
ceph/ceph
fedoraproject/fedora 30
fedoraproject/fedora 31
redhat/ceph_storage 3.0
redhat/ceph_storage 3.3
Published Nov 08, 2019
Tracked Since Feb 18, 2026