A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service.
The product does not properly handle when all or part of an input has been URL encoded.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2139925 | issue tracking |