Lucene search

K
cve[email protected]CVE-2015-5245
HistoryDec 03, 2015 - 8:59 p.m.

CVE-2015-5245

2015-12-0320:59:05
web.nvd.nist.gov
43
cve
2015-5245
crlf injection
ceph object gateway
radosgw
rgw
http response splitting
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.8 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

58.9%

CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted bucket name.

Affected configurations

NVD
Node
redhatcephRange0.94.3
CPENameOperatorVersion
redhat:cephredhat cephle0.94.3

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.8 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

58.9%