GPU VulnDB

Database/Control plane, storage & DevOps

Ceph iSCSI gateway (ceph-iscsi-cli / rbd-target-api): rbd-target-api ships with the Werkzeug debug console enabled

CVE-2018-14649Control plane, storage & DevOpscurated

Impact

rbd-target-api ships with the Werkzeug debug console enabled, which is an interactive Python shell exposed over HTTP with no authentication. Anyone who reaches the port executes arbitrary code as root on the iSCSI gateway node and from there controls the RBD images it serves.

Who can reach it

Any host with network reach to the rbd-target-api port on a Ceph iSCSI gateway. Fully pre-authentication.

What to do

Upgrade ceph-iscsi-cli to the fixed package immediately and restart rbd-target-api. Treat any gateway that was network-reachable as compromised: rebuild it and rotate its CephX keys. Firewall the API to the management network only.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.