CVE-2015-5245
Summary
| CVE | CVE-2015-5245 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-12-03 20:59:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted bucket name. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [Ceph-announce] v0.94.4 Hammer released | af854a3a-2127-422b-91ae-364da2661108 | lists.ceph.com | Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| Bug #12537: [CVE-2015-5245] RGW returns requested bucket name raw in "Bucket" response header - rgw - Ceph | af854a3a-2127-422b-91ae-364da2661108 | tracker.ceph.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| CVE-2015-5245 - Red Hat Customer Portal | MITRE | access.redhat.com | |
| 1261606 – (CVE-2015-5245) CVE-2015-5245 Ceph: RGW returns requested bucket name raw in Bucket response header | MITRE | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.