Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-5245
HistoryDec 03, 2015 - 12:00 a.m.

CVE-2015-5245

2015-12-0300:00:00
ubuntu.com
ubuntu.com
15

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.002 Low

EPSS

Percentile

58.8%

CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or
RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP
headers and conduct HTTP response splitting attacks via a crafted bucket
name.

Bugs

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.002 Low

EPSS

Percentile

58.8%