PT-2018-12640 · Red Hat+1 · Red Hat Ceph Storage+1

Realasmo

·

Published

2018-10-09

·

Updated

2023-02-13

·

CVE-2018-14649

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat Ceph Storage versions 2 and 3
Description The issue allows unauthenticated attackers to access a debug shell and escalate privileges. This is due to the ceph-isci-cli package using python-werkzeug in debug shell mode, enabled by setting debug=True in the /usr/bin/rbd-target-api file. Once connected to the debug shell, attackers can execute arbitrary commands remotely with the same privileges as the user running the application, which in the case of Red Hat Ceph Storage 2 and 3, is root level.
Recommendations For Red Hat Ceph Storage versions 2 and 3, consider disabling the debug shell mode in the python-werkzeug library as a temporary workaround until a patch is available. Restrict access to the /usr/bin/rbd-target-api file to minimize the risk of exploitation. Avoid using the ceph-isci-cli package with root level permissions until the issue is resolved.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2018-14649
RHSA-2018:2837
RHSA-2018:2838

Affected Products

Red Hat Ceph Storage
Python-Werkzeug