VDB
RHSA-2019%3A2579
RHSA-2019%3A2579
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Ceph Storage 3 for Ubuntu |
Timeline
- Aug 28, 2019 CVE Published
- Nov 21, 2025 CVE Updated
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2019:2579 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1739292 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_2579.json advisory
- https://access.redhat.com/security/cve/CVE-2019-10222 advisory
- https://www.cve.org/CVERecord?id=CVE-2019-10222 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10222 advisory
- https://tracker.ceph.com/issues/40018 advisory