CVE-2022-3854 is a denial-of-service vulnerability in Ceph's RGW backends, specifically affecting Red Hat Ceph Storage. An unauthenticated attacker can crash the RGW by providing a null URL, leading to a denial of service. With a CVSS score of 6.5 (Medium), this vulnerability is remotely exploitable with low attack complexity and no user interaction required. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:redhat:ceph_storage:3.0:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:ceph_storage:4.0:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:redhat:ceph_storage:5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-3854
Dec 10, 2024A flaw was found in Ceph relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW causing a denial of service.
Mar 14, 2023ceph: possible DoS issue in ceph URL processing on RGW backends
Nov 3, 2022