RedHat: RHSA-2019-2579:01 Important: ceph security update
Summary
Red Hat Ceph Storage is a scalable, open, software-defined storage platform
that combines the most stable version of the Ceph storage system with a
Ceph management platform, deployment utilities, and support services.
Security Fix(es):
* ceph: Unauthenticated clients can crash ceph RGW configured with beast as
frontend (CVE-2019-10222)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Summary
Solution
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
ingle/installation_guide_for_ubuntu/index#upgrading-the-storage-cluster
References
https://access.redhat.com/security/cve/CVE-2019-10222 https://access.redhat.com/security/updates/classification/#important
Package List
Topic
An update is now available for Red Hat Ceph Storage 3.3 on Ubuntu 16.04.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Topic
Relevant Releases Architectures
Bugs Fixed
1739292 - CVE-2019-10222 ceph: Unauthenticated clients can crash ceph RGW configured with beast as frontend