CVE-2024-47866

HIGH7.5EPSS 0.13%

RGW DoS attack with empty HTTP header in S3 object copy

發布日:2025/11/12修改日:2026/4/30
也稱為:GHSA-mgrm-g92q-f8h8BIT-ceph-2024-47866

描述

Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put an object and specifying an empty string as its content leads to the RGW daemon crashing, resulting in a DoS attack. As of time of publication, no known patched versions exist.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

參考連結(4)