公告ID: KYLIN-2019-3821
安全等级: 重要
产品: Kylin V3
发布日期: 2019年2月11日
CVE: CVE-2019-3821
CVSS3评分: 7.5
概述:
This flaw does not affect ceph version as shipped with Kylin Ceph Storage 2 and Kylin Ceph Storage 3. 描述:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust file descriptors for ceph-radosgw service resulting in a remote denial of service. 系统版本:
KYLIN 3.3.x
受影响包列表:
ceph-common