In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade librados-devel-debuginfoUpgrade rbd-nbd-debuginfoUpgrade ceph-mds-debuginfoUpgrade python-rgwUpgrade ceph-mgr-debuginfoUpgrade ceph-selinuxUpgrade rbd-nbdUpgrade librbd-develUpgrade libcephfs-develUpgrade librados-develUpgrade ceph-debuginfoUpgrade python3-rgw-debuginfoUpgrade ceph-radosgwUpgrade ceph-common-debuginfoUpgrade libradospp-develUpgrade python3-rbd-debuginfoUpgrade rbd-mirrorUpgrade libtcmuUpgrade python-cephfsUpgrade ceph-base-debuginfoUpgrade ceph-fuseUpgrade python-ceph-argparseUpgrade rbd-mirror-debuginfoUpgrade ceph-fuse-debuginfoUpgrade libcephfs2-debuginfoUpgrade rbd-fuse-debuginfoUpgrade ceph-mdsUpgrade ceph-mon-debuginfoUpgrade python3-rados-debuginfoUpgrade python3-radosUpgrade ceph-radosgw-debuginfoUpgrade python3-ceph-argparseUpgrade ceph-grafana-dashboardsUpgrade python3-rbdUpgrade libcephfs2Upgrade gperftools-libsUpgrade ceph-commonUpgrade tcmu-runnerUpgrade gperftools-libs-debuginfoUpgrade ceph-baseUpgrade librgw2-debuginfoUpgrade ceph-osd-debuginfoUpgrade ceph-ansibleUpgrade python3-cephfs-debuginfoUpgrade gperftools-debugsourceUpgrade ceph-debugsourceUpgrade librgw-develUpgrade libradosstriper1Upgrade python3-cephfsUpgrade python3-rgwUpgrade librgw2Upgrade libradosstriper1-debuginfoUpgrade ceph-test-debuginfo | Jun 1, 2021 | Jan 13, 2021 |
| Debian | — | Upgrade tcmu | Jul 30, 2024 | Jan 13, 2021 |
| Redhat_linux | — | Upgrade python3-radosUpgrade python3-rbdUpgrade ceph-common-debuginfoUpgrade ceph-fuse-debuginfoUpgrade tcmu-runnerUpgrade ceph-test-debuginfoUpgrade ceph-ansibleUpgrade librgw2Upgrade ceph-mdsUpgrade libradosstriper1-debuginfoUpgrade python3-cephfsUpgrade python3-cephfs-debuginfoUpgrade python3-rados-debuginfoUpgrade python-rgwUpgrade ceph-radosgw-debuginfoUpgrade ceph-commonUpgrade librgw-develUpgrade ceph-grafana-dashboardsUpgrade libradosstriper1Upgrade python3-ceph-argparseUpgrade ceph-osd-debuginfoUpgrade python3-rgwUpgrade libcephfs2Upgrade gperftools-libs-debuginfoUpgrade ceph-debugsourceUpgrade ceph-selinuxUpgrade ceph-mon-debuginfoUpgrade rbd-fuse-debuginfoUpgrade gperftools-debugsourceUpgrade librgw2-debuginfoUpgrade gperftools-libsUpgrade ceph-fuseUpgrade rbd-nbd-debuginfoUpgrade ceph-base-debuginfoUpgrade librados-develUpgrade librados-devel-debuginfoUpgrade python-ceph-argparseUpgrade rbd-nbdUpgrade ceph-mgr-debuginfoUpgrade python3-rgw-debuginfoUpgrade libtcmuUpgrade ceph-radosgwUpgrade ceph-debuginfoUpgrade ceph-mds-debuginfoUpgrade librbd-develUpgrade libradospp-develUpgrade python3-rbd-debuginfoUpgrade rbd-mirror-debuginfoUpgrade libcephfs-develUpgrade python-cephfsUpgrade rbd-mirrorUpgrade libcephfs2-debuginfoUpgrade ceph-base | Apr 30, 2021 | Jan 13, 2021 |
| Suse | — | Upgrade tcmu-runner-handler-rbdUpgrade libtcmu2Upgrade tcmu-runner | Jan 18, 2021 | Jan 13, 2021 |
| Ubuntu | — | Upgrade libtcmu2Upgrade tcmu-runner | Jan 29, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub