In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade ceph-debuginfoUpgrade python3-rbd-debuginfoUpgrade libtcmuUpgrade python3-rgw-debuginfoUpgrade ceph-base-debuginfoUpgrade librbd-develUpgrade rbd-mirrorUpgrade libcephfs-develUpgrade rbd-mirror-debuginfoUpgrade python-cephfsUpgrade ceph-mgr-debuginfoUpgrade python-rgwUpgrade libradospp-develUpgrade ceph-radosgwUpgrade ceph-mds-debuginfoUpgrade librados-devel-debuginfoUpgrade ceph-selinuxUpgrade rbd-nbd-debuginfoUpgrade ceph-common-debuginfoUpgrade ceph-fuseUpgrade rbd-nbdUpgrade python-ceph-argparseUpgrade librados-develUpgrade libradosstriper1-debuginfoUpgrade librgw2Upgrade ceph-grafana-dashboardsUpgrade python3-cephfsUpgrade python3-ceph-argparseUpgrade tcmu-runnerUpgrade ceph-baseUpgrade python3-radosUpgrade ceph-debugsourceUpgrade gperftools-debugsourceUpgrade ceph-radosgw-debuginfoUpgrade libcephfs2Upgrade gperftools-libsUpgrade ceph-commonUpgrade python3-rbdUpgrade librgw-develUpgrade python3-cephfs-debuginfoUpgrade libcephfs2-debuginfoUpgrade ceph-test-debuginfoUpgrade ceph-fuse-debuginfoUpgrade python3-rados-debuginfoUpgrade rbd-fuse-debuginfoUpgrade ceph-mon-debuginfoUpgrade python3-rgwUpgrade ceph-osd-debuginfoUpgrade ceph-mdsUpgrade gperftools-libs-debuginfoUpgrade ceph-ansibleUpgrade librgw2-debuginfoUpgrade libradosstriper1 | Jun 1, 2021 | Jan 13, 2021 |
| Debian | — | Upgrade tcmu | Jul 30, 2024 | Jan 13, 2021 |
| Redhat_linux | — | Upgrade ceph-common-debuginfoUpgrade rbd-fuse-debuginfoUpgrade libradosstriper1-debuginfoUpgrade librgw2Upgrade tcmu-runnerUpgrade ceph-commonUpgrade ceph-osd-debuginfoUpgrade gperftools-libsUpgrade ceph-grafana-dashboardsUpgrade libradosstriper1Upgrade ceph-radosgw-debuginfoUpgrade python-rgwUpgrade ceph-mon-debuginfoUpgrade ceph-mdsUpgrade ceph-fuse-debuginfoUpgrade ceph-ansibleUpgrade ceph-test-debuginfoUpgrade libcephfs2Upgrade python3-radosUpgrade python3-rbdUpgrade librgw-develUpgrade ceph-debugsourceUpgrade python3-rados-debuginfoUpgrade python3-cephfs-debuginfoUpgrade python3-cephfsUpgrade python3-ceph-argparseUpgrade gperftools-libs-debuginfoUpgrade ceph-selinuxUpgrade librgw2-debuginfoUpgrade gperftools-debugsourceUpgrade python3-rgwUpgrade rbd-nbdUpgrade python3-rbd-debuginfoUpgrade libradospp-develUpgrade ceph-mgr-debuginfoUpgrade ceph-fuseUpgrade librados-devel-debuginfoUpgrade python-cephfsUpgrade ceph-mds-debuginfoUpgrade libcephfs-develUpgrade ceph-base-debuginfoUpgrade librbd-develUpgrade python-ceph-argparseUpgrade rbd-mirror-debuginfoUpgrade rbd-mirrorUpgrade ceph-baseUpgrade ceph-radosgwUpgrade libcephfs2-debuginfoUpgrade libtcmuUpgrade python3-rgw-debuginfoUpgrade ceph-debuginfoUpgrade rbd-nbd-debuginfoUpgrade librados-devel | Apr 30, 2021 | Jan 13, 2021 |
| Suse | — | Upgrade tcmu-runner-handler-rbdUpgrade tcmu-runnerUpgrade libtcmu2 | Jan 18, 2021 | Jan 13, 2021 |
| Ubuntu | — | Upgrade libtcmu2Upgrade tcmu-runner | Jan 29, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub