Database/Control plane, storage & DevOps
Ceph RADOS Gateway (RGW): A POST carrying malformed object-tagging XML dereferences a NULL pointer and kills the
CVSS 7.5CVE-2020-12059Control plane, storage & DevOpscurated
Impact
A POST carrying malformed object-tagging XML dereferences a NULL pointer and kills the gateway. One tenant can knock the shared S3 service over on demand with a single request.
Who can reach it
Any client able to send an HTTP POST to the RGW S3 endpoint.
What to do
Upgrade RGW past 13.2.9 and restart the radosgw daemons. Keep more than one gateway in the pool so a targeted crash does not become a full outage.
References
Related entries
- Ceph RADOS Gateway (RGW): One malformed PUT kills the radosgw process. Sending an object copy with an emptyCVE-2024-47866 · Ceph RADOS Gateway (RGW)High
- Ceph RADOS Gateway (RGW): RGW accepts a JWT whose header declares alg "none" and never checks the signature, so anyoneCVE-2024-48916 · Ceph RADOS Gateway (RGW)High
- Ceph dashboard (ceph-mgr dashboard module): An unauthenticated HTTP request with traversal sequences reads arbitraryCVE-2020-1699 · Ceph dashboard (ceph-mgr dashboard module)High
- IBM Elastic Storage System / Elastic Storage Server (UDP request handling): An unauthenticated attacker who can sendCVE-2020-5015 · IBM Elastic Storage System / Elastic Storage Server (UDP request handling)High
- NetApp Clustered Data ONTAP httpd: A remote attacker with no credentials crashes the ONTAP web server, removingCVE-2021-27005 · NetApp Clustered Data ONTAP httpdHigh
- SPDK iSCSI target (before 20.01.01) and SPDK vhost target (before 19.01): A zero-length PDU sent where data is expectedCVE-2021-28361 · SPDK iSCSI target (before 20.01.01) and SPDK vhost target (before 19.01)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.