Back

MEDIUM

ceph: RGW unauthenticated denial of service

Published May 18, 2021

Description

A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a denial of service. The greatest threat to the system is of availability.

Affected products

Remediation

Red Hat statement

* Red Hat OpenStack Platform deployments use the ceph package directly from the Ceph channel; the RHOSP package will not be updated at this time. * This issue did not affect the versions of ceph as shipped with Red Hat Enterprise Linux 8 as they did not include support for RGW. * Red Hat OpenShift Container Storage (RHOCS) 4 shipped ceph package for the usage of RHOCS 4.2 only, that has reached End Of Life. The shipped version of ceph package is no longer used and supported with the release of RHOCS 4.3.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 18, 2021
Updated Aug 3, 2024
Reserved May 3, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 13, 2021
ENISA EUVD
Assigner redhat
Published May 18, 2021
Updated Aug 3, 2024
Exploited since n/a
EUVD-2021-26847