High severity7.5NVD Advisory· Published Mar 27, 2019· Updated Jun 17, 2026
CVE-2019-3821
CVE-2019-3821
Description
A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust file descriptors for ceph-radosgw service resulting in a remote denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9(expand)+ 1 more
- (no CPE)
- (no CPE)
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
- osv-coords2 versionspkg:rpm/suse/ceph&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1
< 14.2.1.468+g994fd9e0cc-3.3.2+ 1 more
- (no CPE)range: < 14.2.1.468+g994fd9e0cc-3.3.2
- (no CPE)range: < 14.2.1.468+g994fd9e0cc-3.3.2
Patches
Vulnerability mechanics
References
3- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- github.com/ceph/civetweb/pull/33nvdIssue TrackingThird Party Advisory
- usn.ubuntu.com/4035-1/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.