Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4460-1 | ceph security update |
Wed, 31 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat ceph
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:redhat:ceph:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Redhat ceph
|
Thu, 11 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 12 Nov 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Ceph RGW. Using the x-amz-copy-source header to upload an empty object will cause Ceph RGW to crash, leading to availability issues. | Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put an object and specifying an empty string as its content leads to the RGW daemon crashing, resulting in a DoS attack. As of time of publication, no known patched versions exist. |
| Title | rgw: RGW DoS attack with empty HTTP header in S3 object copy | RGW DoS attack with empty HTTP header in S3 object copy |
Wed, 12 Nov 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Ceph RGW. Using the x-amz-copy-source header to upload an empty object will cause Ceph RGW to crash, leading to availability issues. | |
| Title | rgw: RGW DoS attack with empty HTTP header in S3 object copy | |
| First Time appeared |
Redhat
Redhat ceph Storage |
|
| Weaknesses | CWE-20 | |
| CPEs | cpe:/a:redhat:ceph_storage:8.1::el9 | |
| Vendors & Products |
Redhat
Redhat ceph Storage |
|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-11T15:35:30.968Z
Reserved: 2024-10-04T16:00:09.628Z
Link: CVE-2024-47866
Updated: 2025-11-12T19:03:51.423Z
Status : Analyzed
Published: 2025-11-12T19:15:34.867
Modified: 2025-12-31T16:23:56.637
Link: CVE-2024-47866
OpenCVE Enrichment
No data.
Debian DLA