CVE-2019-3821
Last modified
CVE-2019-3821 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust file descriptors for ceph-radosgw service resulting in a remote denial of service.. EPSS estimates a 2.95% chance of exploitation in the next 30 days.
Description
A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust file descriptors for ceph-radosgw service resulting in a remote denial of service.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ceph | Civetweb | < 1.11 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.10 |
| Canonical | Ubuntu Linux | 19.04 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3821Issue Tracking, Third Party Advisory
- https://github.com/ceph/civetweb/pull/33Issue Tracking, Third Party Advisory
- https://usn.ubuntu.com/4035-1/Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3821Issue Tracking, Third Party Advisory
- https://github.com/ceph/civetweb/pull/33Issue Tracking, Third Party Advisory
- https://usn.ubuntu.com/4035-1/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2019-3821?
How severe is CVE-2019-3821?
How do I fix CVE-2019-3821?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-3815A memory leak was discovered in the backport of fixes for CV…3.3
- CVE-2019-3816Openwsman, versions up to and including 2.6.9, are vulnerabl…7.5
- CVE-2019-3817A use-after-free flaw has been discovered in libcomps before…7.5
- CVE-2019-3818The kube-rbac-proxy container before version 0.4.1 as used i…7.5
- CVE-2019-3819A flaw was found in the Linux kernel in the function hid_deb…4.4
- CVE-2019-3820It was discovered that the gnome-shell lock screen since ver…4.3
- CVE-2019-3822libcurl versions from 7.36.0 to before 7.64.0 are vulnerable…9.8
- CVE-2019-3823libcurl versions from 7.34.0 to before 7.64.0 are vulnerable…4.3
- CVE-2019-3824A flaw was found in the way an LDAP search expression could …
- CVE-2019-3825A vulnerability was discovered in gdm before 3.31.4. When ti…6.3
- CVE-2019-3826A stored, DOM based, cross-site scripting (XSS) flaw was fou…6.1
- CVE-2019-3827An incorrect permission check in the admin backend in gvfs b…7
Are you affected by CVE-2019-3821?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
