Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-45695

Опубликовано: 16 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, Kopia's HTTP server started with --without-password accepts unauthenticated requests to /api/v1/repo/exists and forwards attacker-supplied SFTP storage configuration to blob.NewStorage, where externalSSH: true and sshArguments containing -oProxyCommand= can cause exec.CommandContext("ssh") to invoke the command through OpenSSH. This issue is fixed in version 0.23.0.

A flaw was found in Kopia, a cross-platform backup tool. An unauthenticated remote attacker can exploit the HTTP server, when started without a password, by sending specially crafted requests to the /api/v1/repo/exists endpoint. This allows the attacker to forward malicious SFTP storage configurations, which can lead to arbitrary code execution through OpenSSH commands.

Отчет

Red Hat Product Security considers this bug as Moderate as this requires active change of out of box configaration for this bug to be exploitable. There is no common use case under which Kopia HTTP server should be started without a password. The diecrepancy in CVSS scores between Red Hat and NVD comes from the differences in User Interaction, Integrity and Availability. The core bug is merely an unintended information disclosure problem if exploited correctly. There is no way to launch a denial of service or affect the integrity of the service. Therefore the bug is scored lower.

Меры по смягчению последствий

This bug can be rendered unusable by making sure that --without-password is not included in startup options for Kopia HTTP server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Containersrhmtc/openshift-migration-velero-plugin-for-mtc-rhel8Fix deferred
OpenShift API for Data Protectionoadp/oadp-kubevirt-velero-plugin-rhel9Fix deferred
OpenShift API for Data Protectionoadp/oadp-mustgather-rhel9Fix deferred
OpenShift API for Data Protectionoadp/oadp-rhel9-operatorFix deferred
OpenShift API for Data Protectionoadp/oadp-velero-plugin-for-csi-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2501364github.com/kopia/kopia: Kopia: Arbitrary code execution via unauthenticated SFTP configuration in HTTP server.

EPSS

Процентиль: 27%
0.00348
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
23 дня назад

Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, Kopia's HTTP server started with --without-password accepts unauthenticated requests to /api/v1/repo/exists and forwards attacker-supplied SFTP storage configuration to blob.NewStorage, where externalSSH: true and sshArguments containing -oProxyCommand=<cmd> can cause exec.CommandContext("ssh") to invoke the command through OpenSSH. This issue is fixed in version 0.23.0.

CVSS3: 9.8
github
3 месяца назад

Kopia: RCE via SSH ProxyCommand Injection

EPSS

Процентиль: 27%
0.00348
Низкий

6.5 Medium

CVSS3