Database/Control plane, storage & DevOps
Ceph iSCSI gateway (ceph-iscsi-cli / rbd-target-api): rbd-target-api ships with the Werkzeug debug console enabled
Impact
rbd-target-api ships with the Werkzeug debug console enabled, which is an interactive Python shell exposed over HTTP with no authentication. Anyone who reaches the port executes arbitrary code as root on the iSCSI gateway node and from there controls the RBD images it serves.
Who can reach it
Any host with network reach to the rbd-target-api port on a Ceph iSCSI gateway. Fully pre-authentication.
What to do
Upgrade ceph-iscsi-cli to the fixed package immediately and restart rbd-target-api. Treat any gateway that was network-reachable as compromised: rebuild it and rotate its CephX keys. Firewall the API to the management network only.
References
Related entries
- Raritan CommandCenter Secure Gateway (CC-SG), before 8.0.0: CC-SG is Raritan's single-pane-of-glass gateway thatCVE-2018-20687 · Raritan CommandCenter Secure Gateway (CC-SG), before 8.0.0Critical
- Slurm (slurmdbd accounting database daemon): SQL injection into SlurmDBD gives an attacker read and write control ofCVE-2018-7033 · Slurm (slurmdbd accounting database daemon)Critical
- Kemp LoadMaster (LMOS): A flaw in session management lets a remote, unauthenticated attacker bypass the LoadMaster'sCVE-2018-9091 · Kemp LoadMaster (LMOS)Critical
- Slurm (slurmdbd, sacctmgr archive load): A second SQL injection path into SlurmDBD, this one through the 'sacctmgrCVE-2019-12838 · Slurm (slurmdbd, sacctmgr archive load)Critical
- HTCondor (condor_startd, condor_schedd, condor_shadow): One CVE covering four separate authentication failures theCVE-2019-18823 · HTCondor (condor_startd, condor_schedd, condor_shadow)Critical
- Lustre ptlrpc module (server-side client packet validation): A Lustre client can send a crafted RPC that overflows aCVE-2019-20427 · Lustre ptlrpc module (server-side client packet validation)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.