Unrated severityNVD Advisory· Published Apr 22, 2020· Updated Aug 4, 2024
CVE-2020-12059
CVE-2020-12059
Description
An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.
Affected products
15- Ceph/Cephdescription
- osv-coords14 versionspkg:bitnami/cephpkg:rpm/suse/ceph&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/ceph&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/ceph&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/ceph&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208
<= 13.2.9+ 13 more
- (no CPE)range: <= 13.2.9
- (no CPE)range: < 12.2.12+git.1587570958.35d78d0243-2.45.1
- (no CPE)range: < 12.2.12+git.1587570958.35d78d0243-2.45.1
- (no CPE)range: < 12.2.12+git.1587570958.35d78d0243-2.45.1
- (no CPE)range: < 12.2.12+git.1587570958.35d78d0243-2.45.1
- (no CPE)range: < 12.2.12+git.1587570958.35d78d0243-2.45.1
- (no CPE)range: < 12.2.12+git.1587570958.35d78d0243-2.45.1
- (no CPE)range: < 12.2.12+git.1587570958.35d78d0243-2.45.1
- (no CPE)range: < 12.2.12+git.1587570958.35d78d0243-2.45.1
- (no CPE)range: < 12.2.12+git.1587570958.35d78d0243-2.45.1
- (no CPE)range: < 12.2.12+git.1587570958.35d78d0243-2.45.1
- (no CPE)range: < 12.2.12+git.1587570958.35d78d0243-2.45.1
- (no CPE)range: < 12.2.12+git.1587570958.35d78d0243-2.45.1
- (no CPE)range: < 12.2.12+git.1587570958.35d78d0243-2.45.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- usn.ubuntu.com/4528-1/mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2023/10/msg00034.htmlmitremailing-list
- bugzilla.suse.com/show_bug.cgimitre
- docs.ceph.com/docs/master/releases/mimic/mitre
- tracker.ceph.com/issues/44967mitre
News mentions
0No linked articles in our index yet.