← Back to browse · API

CVE-2018-14649

Severity
CRITICAL
CVSS
9.8
EPSS
0.11741
Risk score
43.31
CISA KEV
No
PoC
No
Published
2018-10-09
Modified
2024-08-05
First seen
2026-08-07
Aliases
EUVD-2018-6547, GHSA-VQ9P-965J-5XF8
Products
[UNKNOWN]:ceph-iscsi-cli n/a
Sources
euvd EUVD-2018-6547

Description

It was found that ceph-isci-cli package as shipped by Red Hat Ceph Storage 2 and 3 is using python-werkzeug in debug shell mode. This is done by setting debug=True in file /usr/bin/rbd-target-api provided by ceph-isci-cli package. This allows unauthenticated attackers to access this debug shell and escalate privileges. Once an attacker has successfully connected to this debug shell they will be able to execute arbitrary commands remotely. These commands will run with the same privileges as of user executing the application which is using python-werkzeug with debug shell mode enabled. In - Red Hat Ceph Storage 2 and 3, ceph-isci-cli package runs python-werkzeug library with root level permissions.

References