CVE-2020-12059

Description

An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.284

Associated Vulnerability

VulnerabilityOS Platform
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) ceph-common-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) ceph-common-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP4.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) ceph-common-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) ceph-common-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) ceph-debugsource-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) libcephfs2-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) ceph-debugsource-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) libcephfs2-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) librados2-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) libcephfs2-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) librados2-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) libcephfs2-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) libradosstriper1-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) librados2-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) libradosstriper1-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) librados2-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) librbd1-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) libradosstriper1-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) librbd1-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) libradosstriper1-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) librgw2-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) librbd1-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) librgw2-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) librbd1-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) python-cephfs-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) librgw2-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) python-cephfs-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) librgw2-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) python-rados-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) python-cephfs-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) python-rados-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) python-cephfs-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) python-rbd-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) python-rados-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) python-rbd-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) python-rados-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) python-rgw-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) python-rbd-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP4 ) python-rgw-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) python-rbd-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) python-rgw-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
SUSE-SU-2020:1158-1(SUSE Linux Enterprise Server 12-SP5 ) python-rgw-debuginfo-12.2.12+git.1587570958.35d78d0243-2.45.1.x86_64_SP5.rpmLinux
distributed storage and file system (USN-4528-1) ceph_10.2.11-0ubuntu0.16.04.3_i386.debLinux
distributed storage and file system (USN-4528-1) ceph_10.2.11-0ubuntu0.16.04.3_amd64.debLinux
distributed storage and file system (USN-4528-1) ceph_12.2.13-0ubuntu0.18.04.4_i386.debLinux
distributed storage and file system (USN-4528-1) ceph_12.2.13-0ubuntu0.18.04.4_amd64.debLinux
distributed storage and file system (USN-4528-1) ceph-base_12.2.13-0ubuntu0.18.04.4_i386.debLinux
distributed storage and file system (USN-4528-1) ceph-base_12.2.13-0ubuntu0.18.04.4_amd64.debLinux
distributed storage and file system (USN-4528-1) ceph-common_10.2.11-0ubuntu0.16.04.3_i386.debLinux
distributed storage and file system (USN-4528-1) ceph-common_10.2.11-0ubuntu0.16.04.3_amd64.debLinux
distributed storage and file system (USN-4528-1) ceph-common_12.2.13-0ubuntu0.18.04.4_i386.debLinux
distributed storage and file system (USN-4528-1) ceph-common_12.2.13-0ubuntu0.18.04.4_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234