Skip to main content

Improper Handling of URL Encoding (Hex Encoding)

CVE-2022-3854

Severity Medium
Score 6.5/10

Summary

A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • REQUIRED
  • NONE
  • NONE
  • HIGH

CWE-177 - Improper Handling of URL Encoding (Hex Encoding)

The software does not properly handle when all or part of an input has been URL encoded.

References

Advisory Timeline

  • Published