Security Advisory

CVE-2019-19337

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-12-23 16:18:04
Last updated 2024-08-05 02:16:46
Assigner redhat
State PUBLISHED

Description

A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse this flaw by causing a remote denial of service by sending a specially crafted HTTP Content-Length header to the Ceph RADOS Gateway server.