7.5
CVE-2016-9579
- EPSS 18.59%
- Published 01.08.2018 16:29:00
- Last modified 21.11.2024 03:01:25
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker could use this flaw to cause denial of service by sending a specially-crafted cross-origin HTTP request. Ceph branches 1.3.x and 2.x are affected.
Data is provided by the National Vulnerability Database (NVD)
Redhat ≫ Ceph Storage Version1.3
Redhat ≫ Ceph Storage Mon Version1.3
Redhat ≫ Ceph Storage Mon Version2
Redhat ≫ Ceph Storage Osd Version1.3
Redhat ≫ Ceph Storage Osd Version2
Redhat ≫ Enterprise Linux Desktop Version7.0
Redhat ≫ Enterprise Linux Server Version7.0
Redhat ≫ Enterprise Linux Workstation Version7.0
Redhat ≫ Ceph Storage Version2.0
Redhat ≫ Ceph Storage Version1.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 18.59% | 0.951 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
secalert@redhat.com | 6.5 | 2.8 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.