In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade python3-rados-debuginfoUpgrade ceph-mdsUpgrade rbd-fuse-debuginfoUpgrade python3-rgwUpgrade librgw-develUpgrade libradosstriper1-debuginfoUpgrade ceph-debugsourceUpgrade gperftools-libs-debuginfoUpgrade gperftools-debugsourceUpgrade libradosstriper1Upgrade librgw2-debuginfoUpgrade tcmu-runnerUpgrade python3-radosUpgrade ceph-mon-debuginfoUpgrade ceph-radosgw-debuginfoUpgrade librgw2Upgrade gperftools-libsUpgrade python3-cephfs-debuginfoUpgrade ceph-test-debuginfoUpgrade libcephfs2-debuginfoUpgrade python3-rbdUpgrade ceph-osd-debuginfoUpgrade libcephfs2Upgrade ceph-commonUpgrade ceph-fuse-debuginfoUpgrade python3-cephfsUpgrade ceph-grafana-dashboardsUpgrade python3-ceph-argparseUpgrade ceph-ansibleUpgrade ceph-baseUpgrade ceph-common-debuginfoUpgrade rbd-nbdUpgrade ceph-mgr-debuginfoUpgrade python3-rbd-debuginfoUpgrade ceph-debuginfoUpgrade ceph-fuseUpgrade libcephfs-develUpgrade ceph-radosgwUpgrade ceph-selinuxUpgrade librados-develUpgrade python-cephfsUpgrade python-ceph-argparseUpgrade rbd-mirrorUpgrade rbd-nbd-debuginfoUpgrade librados-devel-debuginfoUpgrade ceph-mds-debuginfoUpgrade ceph-base-debuginfoUpgrade librbd-develUpgrade libtcmuUpgrade rbd-mirror-debuginfoUpgrade python3-rgw-debuginfoUpgrade python-rgwUpgrade libradospp-devel | Jun 1, 2021 | Jan 13, 2021 |
| Debian | — | Upgrade tcmu | Jul 30, 2024 | Jan 13, 2021 |
| Redhat_linux | — | Upgrade gperftools-libs-debuginfoUpgrade ceph-selinuxUpgrade rbd-fuse-debuginfoUpgrade ceph-mon-debuginfoUpgrade python3-rgwUpgrade python3-cephfs-debuginfoUpgrade ceph-radosgw-debuginfoUpgrade ceph-debugsourceUpgrade librgw2Upgrade ceph-grafana-dashboardsUpgrade python3-rados-debuginfoUpgrade ceph-commonUpgrade python-rgwUpgrade python3-rbdUpgrade python3-ceph-argparseUpgrade ceph-osd-debuginfoUpgrade ceph-test-debuginfoUpgrade libradosstriper1-debuginfoUpgrade libradosstriper1Upgrade librgw-develUpgrade gperftools-debugsourceUpgrade libcephfs2Upgrade ceph-mdsUpgrade ceph-ansibleUpgrade gperftools-libsUpgrade tcmu-runnerUpgrade ceph-fuse-debuginfoUpgrade librgw2-debuginfoUpgrade ceph-common-debuginfoUpgrade python3-radosUpgrade python3-cephfsUpgrade python-cephfsUpgrade rbd-nbd-debuginfoUpgrade librbd-develUpgrade python-ceph-argparseUpgrade ceph-fuseUpgrade librados-develUpgrade rbd-nbdUpgrade librados-devel-debuginfoUpgrade ceph-debuginfoUpgrade libradospp-develUpgrade libcephfs-develUpgrade ceph-baseUpgrade rbd-mirror-debuginfoUpgrade libcephfs2-debuginfoUpgrade rbd-mirrorUpgrade ceph-base-debuginfoUpgrade python3-rgw-debuginfoUpgrade ceph-mds-debuginfoUpgrade python3-rbd-debuginfoUpgrade ceph-mgr-debuginfoUpgrade libtcmuUpgrade ceph-radosgw | Apr 30, 2021 | Jan 13, 2021 |
| Suse | — | Upgrade tcmu-runner-handler-rbdUpgrade libtcmu2Upgrade tcmu-runner | Jan 18, 2021 | Jan 13, 2021 |
| Ubuntu | — | Upgrade libtcmu2Upgrade tcmu-runner | Jan 29, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub