Vulnerability Name:

CVE-2019-10222 (CCN-166020)

Assigned:2019-08-28
Published:2019-08-28
Updated:2023-02-12
Summary:
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2019-10222

Source: secalert@redhat.com
Type: Issue Tracking, Mitigation, Patch, Vendor Advisory
secalert@redhat.com

Source: XF
Type: UNKNOWN
ceph-cve201910222-dos(166020)

Source: CCN
Type: Ceph GIT Repository
rgw: asio: check the remote endpoint before processing requests #29967

Source: CCN
Type: oss-sec Mailing List, Wed, 28 Aug 2019 15:27:48 +0000
CVE-2019-10222: ceph: unauthenticated clients can crash RGW

Source: secalert@redhat.com
Type: Vendor Advisory
secalert@redhat.com

Oval Definitions
Definition IDClassTitleLast Modified
oval:org.opensuse.security:def:201910222
V
CVE-2019-10222
2023-06-22
oval:org.opensuse.security:def:7460
P
ceph-common-16.2.11.58+g38d6afd3b78-150400.3.6.1 on GA media (Moderate)
2023-06-12
oval:org.opensuse.security:def:51967
P
Security update for supportutils (Moderate)
2022-11-29
oval:org.opensuse.security:def:51947
P
Security update for protobuf (Important)
2022-11-09
oval:org.opensuse.security:def:624
P
Security update for python-crcmod, python-cryptography, python-cryptography-vectors (Moderate) (in QA)
2022-09-26
oval:org.opensuse.security:def:3534
P
java-1_8_0-ibm-1.8.0_sr5.40-30.54.1 on GA media (Moderate)
2022-06-28
oval:org.opensuse.security:def:3576
P
libasan2-32bit-5.3.1+r233831-12.1 on GA media (Moderate)
2022-06-28
oval:org.opensuse.security:def:3522
P
hardlink-1.0-6.38 on GA media (Moderate)
2022-06-28
oval:org.opensuse.security:def:3564
P
libXrandr2-1.5.0-6.2 on GA media (Moderate)
2022-06-28
oval:org.opensuse.security:def:2874
P
bash-4.4-150400.25.22 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:2877
P
bind-utils-9.16.20-150400.3.6 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:2916
P
enscript-1.6.6-1.17 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:2882
P
bubblewrap-0.4.1-1.16 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:2886
P
ceph-common-16.2.7.654+gd5a90ff46f0-150400.1.4 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:2884
P
c-ares-devel-1.17.1+20200724-3.17.1 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:2857
P
Mesa-21.2.4-150400.66.1 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:2868
P
audit-devel-3.0.6-150400.2.13 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:2924
P
fuse-2.9.7-3.3.1 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:2926
P
gc-devel-7.6.4-1.16 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:2910
P
dracut-055+suse.252.g4988b0bf-150400.1.8 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:94516
P
ceph-common-16.2.7.654+gd5a90ff46f0-150400.1.4 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:2871
P
autoyast2-4.4.36-150400.1.6 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:24
P
ceph-common-15.2.9.83+g4275378de0-3.17.1 on GA media (Moderate)
2022-06-13
oval:org.opensuse.security:def:100393
P
(Important)
2022-03-30
oval:org.opensuse.security:def:953
P
Security update for ldns (Moderate)
2022-03-02
oval:org.opensuse.security:def:112052
P
ceph-16.2.6.45+g8fda9838398-1.1 on GA media (Moderate)
2022-01-17
oval:org.opensuse.security:def:69574
P
Security update for glib-networking (Important)
2021-12-10
oval:org.opensuse.security:def:69570
P
Security update for mariadb (Moderate)
2021-12-06
oval:org.opensuse.security:def:1578
P
Security update for python-Babel (Important)
2021-12-06
oval:org.opensuse.security:def:49456
P
Security update for php72 (Moderate)
2021-11-19
oval:org.opensuse.security:def:64779
P
Security update for rpm (Important)
2021-10-15
oval:org.opensuse.security:def:68678
P
Security update for the Linux Kernel (Important)
2021-10-12
oval:org.opensuse.security:def:105604
P
ceph-16.2.6.45+g8fda9838398-1.1 on GA media (Moderate)
2021-10-01
oval:org.opensuse.security:def:69716
P
Security update for krb5 (Important)
2021-08-20
oval:org.opensuse.security:def:48110
P
libexiv2-12-0.23-12.5.1 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:48231
P
libykcs11-1-1.5.0-3.16 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:48096
P
libass5-0.10.2-3.1 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:48095
P
libasan2-32bit-5.3.1+r233831-12.1 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:71783
P
ceph-common-15.2.9.83+g4275378de0-3.17.1 on GA media (Moderate)
2021-08-09
oval:org.opensuse.security:def:72018
P
pam_yubico-2.26-1.7 on GA media (Moderate)
2021-08-09
oval:org.opensuse.security:def:100800
P
ceph-common-15.2.9.83+g4275378de0-3.17.1 on GA media (Moderate)
2021-08-09
oval:org.opensuse.security:def:72060
P
rsyslog-8.39.0-4.10.1 on GA media (Moderate)
2021-08-09
oval:org.opensuse.security:def:62042
P
ceph-common-15.2.9.83+g4275378de0-3.17.1 on GA media (Moderate)
2021-08-09
oval:org.opensuse.security:def:68213
P
Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP2) (Important)
2021-07-16
oval:org.opensuse.security:def:69679
P
Security update for wireshark (Important)
2021-06-22
oval:org.opensuse.security:def:69675
P
Security update for python-rsa (Important)
2021-06-17
oval:org.opensuse.security:def:48556
P
libtag1-1.9.1-1.218 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:48648
P
xalan-j2-2.7.0-264.38 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:51905
P
Security update for apache2-mod_auth_openidc (Important)
2021-06-08
oval:org.opensuse.security:def:48796
P
libpcsclite1-32bit-1.8.10-3.7 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:48424
P
gdm-3.10.0.1-52.5 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:69611
P
Security update for nghttp2 (Important)
2021-03-24
oval:org.opensuse.security:def:68113
P
Security update for the Linux Kernel (Live Patch 13 for SLE 15 SP1) (Important)
2021-03-17
oval:org.opensuse.security:def:52009
P
Security update for java-1_7_1-ibm (Important)
2021-02-18
oval:org.opensuse.security:def:99916
P
(Moderate)
2020-12-09
oval:org.opensuse.security:def:71566
P
libjansson-devel-2.9-1.24 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:107059
P
ceph-common-15.2.2.18+g1dbcddb5d8-1.10 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:49010
P
libgadu3-1.11.4-1.12 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:49011
P
libgio-fam-2.48.2-12.15.1 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:116617
P
ceph-common-15.2.2.18+g1dbcddb5d8-1.10 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:61713
P
ceph-common-15.2.2.18+g1dbcddb5d8-1.10 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:2216
P
squid-4.11-5.17.2 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:72134
P
gstreamer-devel-1.12.5-1.17 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:72176
P
libmpg123-0-1.25.10-1.38 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:93680
P
ceph-common-15.2.2.18+g1dbcddb5d8-1.10 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:71454
P
ceph-common-15.2.2.18+g1dbcddb5d8-1.10 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:71453
P
cairo-devel-1.16.0-1.55 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:2845
P
Security update for MozillaFirefox (Important)
2020-12-02
oval:org.opensuse.security:def:2793
P
Security update for webkit2gtk3 (Important)
2020-12-02
oval:org.opensuse.security:def:2844
P
Security update for libX11 (Important)
2020-12-02
oval:org.opensuse.security:def:2815
P
Security update for libjpeg-turbo (Important)
2020-12-02
oval:org.opensuse.security:def:2797
P
Security update for openexr (Moderate)
2020-12-02
oval:org.opensuse.security:def:2835
P
Security update for file-roller (Low)
2020-12-02
oval:org.opensuse.security:def:2829
P
Security update for python (Moderate)
2020-12-02
oval:org.opensuse.security:def:2839
P
Security update for openexr (Moderate)
2020-12-02
oval:org.opensuse.security:def:2803
P
Security update for wavpack (Low)
2020-12-02
oval:org.opensuse.security:def:49498
P
NetworkManager on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:49156
P
libXxf86dga-devel on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:68720
P
Security update for the Linux Kernel (Important)
2020-12-01
oval:org.opensuse.security:def:49310
P
python3-SQLAlchemy on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:50062
P
gtk-vnc-devel on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:49323
P
rpcbind on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:50653
P
Security update for ceph (Important)
2020-12-01
oval:org.opensuse.security:def:49661
P
libdjvulibre-devel on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:50525
P
Security update for systemd (Important)
2020-12-01
oval:org.opensuse.security:def:50432
P
Security update for java-11-openjdk (Important)
2020-12-01
oval:org.opensuse.security:def:66268
P
Security update for the Linux Kernel (Important)
2020-12-01
oval:org.opensuse.security:def:49353
P
wget on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:65434
P
Security update for ceph (Important)
2020-12-01
oval:org.opensuse.security:def:50598
P
Security update for python3 (Moderate)
2020-12-01
oval:org.opensuse.security:def:50460
P
Security update for the Linux Kernel (Important)
2020-12-01
oval:org.opensuse.security:def:49329
P
shadow on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:49352
P
w3m on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:50104
P
uuidd on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:68781
P
Security update for ceph (Important)
2020-12-01
oval:org.opensuse.security:def:50629
P
Security update for bzip2 (Important)
2020-12-01
oval:org.opensuse.security:def:49703
P
libwebp-devel on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:50567
P
Security update for python3 (Important)
2020-12-01
oval:org.opensuse.security:def:50300
P
Security update for zsh (Important)
2020-12-01
oval:org.opensuse.security:def:50599
P
Security update for bluez (Moderate)
2020-12-01
oval:org.opensuse.security:def:65476
P
Security update for ceph, ceph-iscsi, ses-manual_en (Moderate)
2020-12-01
oval:org.opensuse.security:def:49807
P
python3-tools on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:50502
P
Security update for java-11-openjdk (Important)
2020-12-01
oval:org.opensuse.security:def:49371
P
containerd on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:49094
P
freetype2-devel on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:65344
P
Security update for java-1_8_0-openjdk (Important)
2020-12-01
oval:org.opensuse.security:def:68823
P
Security update for ceph, ceph-iscsi, ses-manual_en (Moderate)
2020-12-01
oval:org.opensuse.security:def:49905
P
cloud-init on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:50671
P
Security update for jasper (Moderate)
2020-12-01
oval:org.opensuse.security:def:49252
P
libupsclient1 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:50342
P
Security update for salt (Important)
2020-12-01
oval:org.opensuse.security:def:72933
P
Security update for samba (Moderate)
2020-12-01
oval:org.opensuse.security:def:66360
P
ceph-common on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:49849
P
ncurses-devel-32bit on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:49065
P
ceph-common on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:49221
P
libprocps7 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:50390
P
Security update for curl (Important)
2020-12-01
oval:org.opensuse.security:def:65386
P
Security update for the Linux Kernel (Important)
2020-12-01
oval:org.opensuse.security:def:49311
P
python3-Werkzeug on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:49947
P
gnuplot on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:64866
P
Security update for ceph (Important)
2020-12-01
oval:org.opensuse.security:def:50556
P
Recommended update for xen (Important)
2020-12-01
oval:org.opensuse.security:def:73051
P
ceph-common on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:99920
P
(Moderate)
2020-02-24
oval:com.ubuntu.disco:def:2019102220000000
V
CVE-2019-10222 on Ubuntu 19.04 (disco) - medium.
2019-11-08
oval:com.ubuntu.bionic:def:2019102220000000
V
CVE-2019-10222 on Ubuntu 18.04 LTS (bionic) - medium.
2019-11-08
oval:org.opensuse.security:def:97807
P
Security update for ceph, ceph-iscsi, ses-manual_en (Moderate)
2019-10-22
oval:org.opensuse.security:def:90842
P
Security update for ceph, ceph-iscsi, ses-manual_en (Moderate)
2019-10-22
oval:org.opensuse.security:def:104497
P
Security update for ceph, ceph-iscsi, ses-manual_en (Moderate)
2019-10-22
oval:org.opensuse.security:def:90800
P
Security update for ceph (Important)
2019-08-28
oval:org.opensuse.security:def:103847
P
Security update for ceph (Important)
2019-08-28
oval:org.opensuse.security:def:104455
P
Security update for ceph (Important)
2019-08-28
oval:org.opensuse.security:def:90192
P
Security update for ceph (Important)
2019-08-28
oval:org.opensuse.security:def:97765
P
Security update for ceph (Important)
2019-08-28
BACK