SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Werkzeug Debug System Command Execution

Category: WEB-ATTACKS      

It was found that ceph-isci-cli package as shipped by Red Hat Ceph Storage 2 and 3 is using python-werkzeug in debug shell mode. This allows unauthenticated attackers to access this debug shell and escalate privileges.


Relevant Information