{
  "threat_severity" : "Important",
  "public_date" : "2025-11-12T00:00:00Z",
  "bugzilla" : {
    "description" : "rgw: RGW DoS attack with empty HTTP header in S3 object copy",
    "id" : "2392386",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2392386"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-20",
  "details" : [ "Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put an object and specifying an empty string as its content leads to the RGW daemon crashing, resulting in a DoS attack. As of time of publication, no known patched versions exist.", "A flaw was found in Ceph RGW. Using the x-amz-copy-source header to upload an empty object will cause Ceph RGW to crash, leading to availability issues." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Ceph Storage 7.1",
    "release_date" : "2026-02-17T00:00:00Z",
    "advisory" : "RHSA-2026:2769",
    "cpe" : "cpe:/a:redhat:ceph_storage:7.1::el8",
    "package" : "ceph-2:18.2.1-381.el8cp"
  }, {
    "product_name" : "Red Hat Ceph Storage 8.1",
    "release_date" : "2025-11-12T00:00:00Z",
    "advisory" : "RHSA-2025:21068",
    "cpe" : "cpe:/a:redhat:ceph_storage:8.1::el9",
    "package" : "ceph-2:19.2.1-292.el9cp"
  }, {
    "product_name" : "Red Hat Ceph Storage 8",
    "release_date" : "2025-11-12T00:00:00Z",
    "advisory" : "RHSA-2025:21203",
    "cpe" : "cpe:/a:redhat:ceph_storage:8::el9",
    "package" : "rhceph/rhceph-8-rhel9:sha256:5a97e827c48732775a76e2fe25860488e773f4d8da0e0fbc51168fe30a5deb4b"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Ceph Storage 4",
    "fix_state" : "Out of support scope",
    "package_name" : "ceph",
    "cpe" : "cpe:/a:redhat:ceph_storage:4"
  }, {
    "product_name" : "Red Hat Ceph Storage 5",
    "fix_state" : "Out of support scope",
    "package_name" : "ceph",
    "cpe" : "cpe:/a:redhat:ceph_storage:5"
  }, {
    "product_name" : "Red Hat Ceph Storage 6",
    "fix_state" : "Will not fix",
    "package_name" : "ceph",
    "cpe" : "cpe:/a:redhat:ceph_storage:6"
  }, {
    "product_name" : "Red Hat Ceph Storage 9",
    "fix_state" : "Affected",
    "package_name" : "rgw",
    "cpe" : "cpe:/a:redhat:ceph_storage:9"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2024-47866\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-47866\nhttps://github.com/ceph/ceph/security/advisories/GHSA-mgrm-g92q-f8h8" ],
  "name" : "CVE-2024-47866",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}