ceph-iscsi-cli: rbd-target-api service runs in debug mode allowing for remote command execution
Published Oct 9, 2018
9.8
CRITICALCVSS 3.0
EPSS 11.74%
Description
It was found that ceph-isci-cli package as shipped by Red Hat Ceph Storage 2 and 3 is using python-werkzeug in debug shell mode. This is done by setting debug=True in file /usr/bin/rbd-target-api provided by ceph-isci-cli package. This allows unauthenticated attackers to access this debug shell and escalate privileges. Once an attacker has successfully connected to this debug shell they will be able to execute arbitrary commands remotely. These commands will run with the same privileges as of user executing the application which is using python-werkzeug with debug shell mode enabled. In - Red Hat Ceph Storage 2 and 3, ceph-isci-cli package runs python-werkzeug library with root level permissions.
Affected products
- Vendor n/a Product Ceph-Iscsi-Cli Defaultn/a
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| n/a | Ceph-Iscsi-Cli | n/a |
|
Configuration 1
- 7.0
- 7.0
- 7.0
Configuration 2
- 2.0
- 3.0
Configuration 3
- n/a
No data.
Red Hat Ceph Storage 2.5 for Red Hat Enterprise Linux 7
ceph-iscsi-cli-0:2.0-7.el7cp
Fixed · RHSA-2018:2837
Red Hat Ceph Storage 3.1
ceph-iscsi-cli-0:2.7-7.el7cp
Fixed · RHSA-2018:2838
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 2.5 for Red Hat Enterprise Linux 7 | ceph-iscsi-cli-0:2.0-7.el7cp | Fixed | RHSA-2018:2837 |
| Red Hat Ceph Storage 3.1 | ceph-iscsi-cli-0:2.7-7.el7cp | Fixed | RHSA-2018:2838 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of ceph-iscsi-cli as shipped with Red Hat Ceph Storage 2 and 3. This flaw does not affect python-werkzeug library. It depends on if application uses python-werkzeug library with debug mode enabled.
Red Hat mitigation
To stop werkzeug debug mode started by rbd-target-api which is provided by ceph-iscsi-cli: 1. ~]# systemctl stop rbd-target-api 2. ~]# vi /usr/bin/rbd-target-api # Start the API server ... 737 app.run(host='0.0.0.0', 738 port=settings.config.api_port, 739 debug=True, <==== change this to debug=False use_evalex=False, <=== add this line to disable debugger code execution 740 use_reloader=False, 741 ssl_context=context) ... after changes it should be # Start the API server ... 737 app.run(host='0.0.0.0', 738 port=settings.config.api_port, 739 debug=False, use_evalex=False, 740 use_reloader=False, 741 ssl_context=context) ... 3. ~]# systemctl start rbd-target-api 4. Limit exposure of port 5000/tcp: This port should be opened to trusted hosts which require to run 'gwcli'.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (31 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 11.74% (0.11741) | 95.96th | v5 (v2026.06.15) |
| Jun 15, 2026 | 11.65% (0.11647) | 95.49th | v5 (v2026.06.15) |
| Apr 25, 2026 | 57.07% (0.57068) | 98.15th | v4 (v2025.03.14) |
| Nov 21, 2025 | 58.11% (0.58114) | 98.07th | v4 (v2025.03.14) |
| Nov 18, 2025 | 62.58% (0.62582) | 98.35th | v4 (v2025.03.14) |
| Aug 17, 2025 | 58.11% (0.58114) | 98.10th | v4 (v2025.03.14) |
| Apr 6, 2025 | 64.24% (0.64236) | 98.30th | v4 (v2025.03.14) |
| Mar 30, 2025 | 68.69% (0.68693) | 98.51th | v4 (v2025.03.14) |
| Mar 29, 2025 | 61.80% (0.61800) | 97.63th | v4 (v2025.03.14) |
| Mar 17, 2025 | 68.69% (0.68693) | 98.52th | v4 (v2025.03.14) |
| Jan 12, 2025 | 14.36% (0.14358) | 95.73th | v3 (v2023.03.01) |
| Dec 17, 2024 | 10.67% (0.10675) | 95.04th | v3 (v2023.03.01) |
| Jul 24, 2024 | 32.95% (0.32945) | 97.08th | v3 (v2023.03.01) |
| May 28, 2024 | 40.38% (0.40376) | 97.27th | v3 (v2023.03.01) |
| Mar 1, 2024 | 44.17% (0.44173) | 97.26th | v3 (v2023.03.01) |
| Feb 8, 2024 | 56.22% (0.56216) | 97.56th | v3 (v2023.03.01) |
| Jan 18, 2024 | 63.37% (0.63367) | 97.57th | v3 (v2023.03.01) |
| Oct 3, 2023 | 69.64% (0.69641) | 97.62th | v3 (v2023.03.01) |
| Jul 8, 2023 | 68.64% (0.68644) | 97.51th | v3 (v2023.03.01) |
| May 25, 2023 | 63.41% (0.63410) | 97.31th | v3 (v2023.03.01) |
| Mar 7, 2023 | 69.28% (0.69276) | 97.39th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.11% (0.01108) | 55.18th | v2 (v2022.01.01) |
| Feb 13, 2023 | 1.11% (0.01108) | 54.62th | v2 (v2022.01.01) |
| Feb 3, 2023 | 3.81% (0.03806) | 85.19th | v2 (v2022.01.01) |
| Sep 17, 2022 | 1.11% (0.01108) | 53.57th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.11% (0.01108) | 51.54th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.11% (0.01108) | 29.61th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.89% (0.02888) | 63.67th | v1 |
| Jan 6, 2022 | 2.89% (0.02888) | 63.32th | v1 |
| Sep 1, 2021 | 2.89% (0.02888) | 80.75th | v1 |
| Apr 14, 2021 | 2.89% (0.02888) | 0.00th | v1 |
References (11)
- http://www.securityfocus.com/bid/105434 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/articles/3623521 x_refsource_CONFIRMMitigationPatchVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2837 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2838 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2018-14649 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1632078 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14649 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://github.com/ceph/ceph-iscsi-cli/issues/120 x_refsource_CONFIRMExploitThird Party Advisory
- https://github.com/ceph/ceph-iscsi-cli/pull/121/commits/c3812075e30c76a800a961e7291087d357403f6b x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-14649
- https://www.cve.org/CVERecord?id=CVE-2018-14649
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/105434 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/articles/3623521 | x_refsource_CONFIRMMitigationPatchVendor Advisory | |
| https://access.redhat.com/errata/RHSA-2018:2837 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/errata/RHSA-2018:2838 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2018-14649 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1632078 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14649 | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| https://github.com/ceph/ceph-iscsi-cli/issues/120 | x_refsource_CONFIRMExploitThird Party Advisory | |
| https://github.com/ceph/ceph-iscsi-cli/pull/121/commits/c3812075e30c76a800a961e7291087d357403f6b | x_refsource_CONFIRMPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-14649 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-14649 |
Change history (0)
No recorded changes yet.