Database/Control plane, storage & DevOps
Ceph iSCSI gateway (ceph-iscsi-cli / rbd-target-api): rbd-target-api ships with the Werkzeug debug console enabled
Impact
rbd-target-api ships with the Werkzeug debug console enabled, which is an interactive Python shell exposed over HTTP with no authentication. Anyone who reaches the port executes arbitrary code as root on the iSCSI gateway node and from there controls the RBD images it serves.
Who can reach it
Any host with network reach to the rbd-target-api port on a Ceph iSCSI gateway. Fully pre-authentication.
What to do
Upgrade ceph-iscsi-cli to the fixed package immediately and restart rbd-target-api. Treat any gateway that was network-reachable as compromised: rebuild it and rotate its CephX keys. Firewall the API to the management network only.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.