Описание
Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, Kopia's HTTP server started with --without-password accepts unauthenticated requests to /api/v1/repo/exists and forwards attacker-supplied SFTP storage configuration to blob.NewStorage, where externalSSH: true and sshArguments containing -oProxyCommand= can cause exec.CommandContext("ssh") to invoke the command through OpenSSH. This issue is fixed in version 0.23.0.
A flaw was found in Kopia, a cross-platform backup tool. An unauthenticated remote attacker can exploit the HTTP server, when started without a password, by sending specially crafted requests to the /api/v1/repo/exists endpoint. This allows the attacker to forward malicious SFTP storage configurations, which can lead to arbitrary code execution through OpenSSH commands.
Отчет
Red Hat Product Security considers this bug as Moderate as this requires active change of out of box configaration for this bug to be exploitable. There is no common use case under which Kopia HTTP server should be started without a password. The diecrepancy in CVSS scores between Red Hat and NVD comes from the differences in User Interaction, Integrity and Availability. The core bug is merely an unintended information disclosure problem if exploited correctly. There is no way to launch a denial of service or affect the integrity of the service. Therefore the bug is scored lower.
Меры по смягчению последствий
This bug can be rendered unusable by making sure that --without-password is not included in startup options for Kopia HTTP server.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Migration Toolkit for Containers | rhmtc/openshift-migration-velero-plugin-for-mtc-rhel8 | Fix deferred | ||
| OpenShift API for Data Protection | oadp/oadp-kubevirt-velero-plugin-rhel9 | Fix deferred | ||
| OpenShift API for Data Protection | oadp/oadp-mustgather-rhel9 | Fix deferred | ||
| OpenShift API for Data Protection | oadp/oadp-rhel9-operator | Fix deferred | ||
| OpenShift API for Data Protection | oadp/oadp-velero-plugin-for-csi-rhel9 | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, Kopia's HTTP server started with --without-password accepts unauthenticated requests to /api/v1/repo/exists and forwards attacker-supplied SFTP storage configuration to blob.NewStorage, where externalSSH: true and sshArguments containing -oProxyCommand=<cmd> can cause exec.CommandContext("ssh") to invoke the command through OpenSSH. This issue is fixed in version 0.23.0.
EPSS
6.5 Medium
CVSS3