CVE-2018-7262 PUBLISHED CVSS 5 MEDIUM

In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service.

EPSS 1.54% · 81.2th percentile

Risk Scores

CVSS v2.0
5
EPSS Score
1.54%
81.2th percentile

Affected Products

VendorProductVersions
redhatceph0, 13.0.0, 13.0.1
fedoraprojectfedora27
n/an/an/a

Timeline

References

Open in Interactive Console →