ceph: Object Gateway server DoS by sending invalid cross-origin HTTP request
Published Aug 1, 2018
7.5
HIGHCVSS 3.0
EPSS 4.40%
Description
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker could use this flaw to cause denial of service by sending a specially-crafted cross-origin HTTP request. Ceph branches 1.3.x and 2.x are affected.
Affected products
-
- Version 1.3 and 2StatusaffectedConstraints-
- Version
Configuration 1
- 1.3
- 1.3
- 2
- 1.3
- 2
- 7.0
- 7.0
- 7.0
Configuration 2
- 2.0
Running on/with
- 16.04
- 7.0
Configuration 3
- 1.3
Running on/with
- 14.04
- 7.0
No data.
Red Hat Ceph Storage 1.3 for Red Hat Enterprise Linux 7
ceph-1:0.94.9-9.el7cp
Fixed · RHSA-2016:2994
Red Hat Ceph Storage 1.3 for Ubuntu
ceph
Fixed · RHSA-2016:2995
Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7
ceph-1:10.2.3-17.el7cp
Fixed · RHSA-2016:2954
Red Hat Ceph Storage 2 for Ubuntu
n/a
Fixed · RHSA-2016:2956
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)
ceph
Not affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)
ceph
Not affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer
ceph
Not affected
Red Hat OpenStack Platform 10 (Newton)
puppet-ceph
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 1.3 for Red Hat Enterprise Linux 7 | ceph-1:0.94.9-9.el7cp | Fixed | RHSA-2016:2994 |
| Red Hat Ceph Storage 1.3 for Ubuntu | ceph | Fixed | RHSA-2016:2995 |
| Red Hat Ceph Storage 2 for Red Hat Enterprise Linux 7 | ceph-1:10.2.3-17.el7cp | Fixed | RHSA-2016:2954 |
| Red Hat Ceph Storage 2 for Ubuntu | n/a | Fixed | RHSA-2016:2956 |
| Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | ceph | Not affected | n/a |
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | ceph | Not affected | n/a |
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer | ceph | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | puppet-ceph | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.40% (0.04396) | 91.01th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.40% (0.04396) | 90.03th | v5 (v2026.06.15) |
| Oct 29, 2025 | 18.01% (0.18013) | 94.87th | v4 (v2025.03.14) |
| Apr 26, 2025 | 19.14% (0.19136) | 94.97th | v4 (v2025.03.14) |
| Mar 30, 2025 | 23.98% (0.23981) | 95.57th | v4 (v2025.03.14) |
| Mar 29, 2025 | 38.38% (0.38375) | 95.82th | v4 (v2025.03.14) |
| Mar 17, 2025 | 23.98% (0.23981) | 95.58th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.67% (0.00674) | 80.50th | v3 (v2023.03.01) |
| May 3, 2024 | 0.67% (0.00674) | 79.70th | v3 (v2023.03.01) |
| Dec 23, 2023 | 0.67% (0.00674) | 77.62th | v3 (v2023.03.01) |
| Nov 10, 2023 | 1.00% (0.01000) | 81.89th | v3 (v2023.03.01) |
| Jul 26, 2023 | 0.99% (0.00993) | 81.55th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.94% (0.00938) | 80.67th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.32% (0.01319) | 71.27th | v2 (v2022.01.01) |
| Feb 13, 2023 | 1.32% (0.01319) | 70.74th | v2 (v2022.01.01) |
| Feb 3, 2023 | 3.78% (0.03779) | 85.12th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.32% (0.01319) | 69.22th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.32% (0.01319) | 44.98th | v2 (v2022.01.01) |
References (11)
- http://rhn.redhat.com/errata/RHSA-2016-2954.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2956.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2994.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2995.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://tracker.ceph.com/issues/18187 x_refsource_CONFIRMExploitPatchVendor Advisory
- http://www.securityfocus.com/bid/94936 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2016-9579 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1403245 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9579 x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-9579
- https://www.cve.org/CVERecord?id=CVE-2016-9579
| Link | Providers | Tags |
|---|---|---|
| http://rhn.redhat.com/errata/RHSA-2016-2954.html | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| http://rhn.redhat.com/errata/RHSA-2016-2956.html | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| http://rhn.redhat.com/errata/RHSA-2016-2994.html | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| http://rhn.redhat.com/errata/RHSA-2016-2995.html | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| http://tracker.ceph.com/issues/18187 | x_refsource_CONFIRMExploitPatchVendor Advisory | |
| http://www.securityfocus.com/bid/94936 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2016-9579 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1403245 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9579 | x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2016-9579 | ||
| https://www.cve.org/CVERecord?id=CVE-2016-9579 |
Change history (0)
No recorded changes yet.