Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-3854
HistoryMar 06, 2023 - 12:00 a.m.

CVE-2022-3854

2023-03-0600:00:00
ubuntu.com
ubuntu.com
17
ceph
url processing
rgw
denial of service
vulnerability

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

29.1%

A flaw was found in Ceph, relating to the URL processing on RGW backends.
An attacker can exploit the URL processing by providing a null URL to crash
the RGW, causing a denial of service.

Bugs

Notes

Author Note
mdeslaur introduced in 16.1 This is fixed in jammy-updates and kinetic-updates, but is not yet in the -security pocket.
OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchceph< 17.2.5-0ubuntu0.22.04.3UNKNOWN
ubuntu22.10noarchceph< 17.2.5-0ubuntu0.22.10.3UNKNOWN

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

29.1%