Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put an object and specifying an empty string as its content leads to the RGW daemon crashing, resulting in a DoS attack. As of time of publication, no known patched versions exist.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 12 Nov 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Ceph RGW. Using the x-amz-copy-source header to upload an empty object will cause Ceph RGW to crash, leading to availability issues. | Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put an object and specifying an empty string as its content leads to the RGW daemon crashing, resulting in a DoS attack. As of time of publication, no known patched versions exist. |
| Title | rgw: RGW DoS attack with empty HTTP header in S3 object copy | RGW DoS attack with empty HTTP header in S3 object copy |
Wed, 12 Nov 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Ceph RGW. Using the x-amz-copy-source header to upload an empty object will cause Ceph RGW to crash, leading to availability issues. | |
| Title | rgw: RGW DoS attack with empty HTTP header in S3 object copy | |
| First Time appeared |
Redhat
Redhat ceph Storage |
|
| Weaknesses | CWE-20 | |
| CPEs | cpe:/a:redhat:ceph_storage:8.1::el9 | |
| Vendors & Products |
Redhat
Redhat ceph Storage |
|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-12T19:03:51.423Z
Reserved: 2024-10-04T16:00:09.628Z
Link: CVE-2024-47866
No data.
Status : Received
Published: 2025-11-12T19:15:34.867
Modified: 2025-11-12T19:15:34.867
Link: CVE-2024-47866