Back

CRITICAL

ceph-iscsi-cli: rbd-target-api service runs in debug mode allowing for remote command execution

Published Oct 9, 2018

Description

It was found that ceph-isci-cli package as shipped by Red Hat Ceph Storage 2 and 3 is using python-werkzeug in debug shell mode. This is done by setting debug=True in file /usr/bin/rbd-target-api provided by ceph-isci-cli package. This allows unauthenticated attackers to access this debug shell and escalate privileges. Once an attacker has successfully connected to this debug shell they will be able to execute arbitrary commands remotely. These commands will run with the same privileges as of user executing the application which is using python-werkzeug with debug shell mode enabled. In - Red Hat Ceph Storage 2 and 3, ceph-isci-cli package runs python-werkzeug library with root level permissions.

Affected products

Remediation

Red Hat statement

This issue affects the versions of ceph-iscsi-cli as shipped with Red Hat Ceph Storage 2 and 3. This flaw does not affect python-werkzeug library. It depends on if application uses python-werkzeug library with debug mode enabled.

Red Hat mitigation

To stop werkzeug debug mode started by rbd-target-api which is provided by ceph-iscsi-cli: 1. ~]# systemctl stop rbd-target-api 2. ~]# vi /usr/bin/rbd-target-api # Start the API server ... 737 app.run(host='0.0.0.0', 738 port=settings.config.api_port, 739 debug=True, <==== change this to debug=False use_evalex=False, <=== add this line to disable debugger code execution 740 use_reloader=False, 741 ssl_context=context) ... after changes it should be # Start the API server ... 737 app.run(host='0.0.0.0', 738 port=settings.config.api_port, 739 debug=False, use_evalex=False, 740 use_reloader=False, 741 ssl_context=context) ... 3. ~]# systemctl start rbd-target-api 4. Limit exposure of port 5000/tcp: This port should be opened to trusted hosts which require to run 'gwcli'.

Metrics

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 9, 2018
Updated Aug 5, 2024
Reserved Jul 27, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Sep 24, 2018