All errata/sisyphus/ALT-PU-2015-1896-1
ALT-PU-2015-1896-1

Package update ceph in branch sisyphus

Version0.94.4-alt1
Published2015-10-20
Max severityMEDIUM
Severity:

Closed issues (2)

CVE-2015-5245
MEDIUM4.3

CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted bucket name.

Published: 2015-12-03Modified: 2025-04-12
CVSS 2.0MEDIUM 4.3
CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N