CVE-2014-8174: Infoleak
eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files.
Other sources
Kurt Seifried of Red Hat reports:
edeploy uses HTTP to download a large number of sensitive files which can lead to code execution:
./ansible/edeploy-install.yml: value=http://{{ ansibledefaultipv4["address"] }}/ ./build/base.install: echo "Acquire { Retries \"0\"; HTTP { Proxy \"http://${HTTPPROXY}\"; }; };" >> "$target/etc/apt/apt.conf.d/01proxy" ./build/base.install: curl -o ${target}/tmp/tar.deb http://ftp.debian.org/debian/pool/main/t/tar/tar1.27.1-1~bpo70+1${ARCH:=amd64}.deb ./build/base.install: echo "deb http://security.ubuntu.com/ubuntu $dist-security main universe multiverse" >> ${target}/etc/apt/sources.list ./build/base.install: echo "deb http://security.debian.org/ $dist/updates main" > ${target}/etc/apt/sources.list.d/updates.list ./build/base.install: wget -O - http://hwraid.le-vert.net/debian/hwraid.le-vert.net.gpg.key | dochroot $target apt-key add - ./build/base.install: echo "deb http://hwraid.le-vert.net/debian ${dist} main" > $target/etc/apt/sources.list.d/hwraid.list ./build/base.install: wget -O - http://hwraid.le-vert.net/ubuntu/hwraid.le-vert.net.gpg.key | dochroot $target apt-key add - ./build/base.install: echo "deb http://hwraid.le-vert.net/ubuntu precise main" > $target/etc/apt/sources.list.d/hwraid.list ./build/base.install: wget -O - http://hwraid.le-vert.net/ubuntu/hwraid.le-vert.net.gpg.key | dochroot $target apt-key add - ./build/base.install: echo "deb http://hwraid.le-vert.net/ubuntu ${dist} main" > $target/etc/apt/sources.list.d/hwraid.list ./build/base.install: wget --no-verbose http://downloads.linux.hp.com/SDR/downloads/MCP/pool/non-free/$packagename -O $target/../../$packagename ./build/base.install: http://downloads.linux.hp.com/SDR/downloads/ServicePackforProLiant/2013.02.0/hp/swpackages/hpacucli-9.40-12.0.x8664.rpm ./build/base.install: dochroot $dir rpm --import http://downloads.linux.hp.com/SDR/hpPublicKey1024.pub ./build/base.install: dochroot $dir rpm --import http://downloads.linux.hp.com/SDR/hpPublicKey2048.pub ./build/base.install:baseurl=http://downloads.linux.hp.com/repo/spp/rhel/$CODENAMEMAJOR.$CODENAMEMINOR/x8664/current ./build/common: wget --no-verbose http://us.archive.ubuntu.com/ubuntu/ubuntu/pool/universe/libm/libmlx4/$LIBMLX ./build/health-check.install: PACKAGES="$PACKAGES numpy http://pkgs.repoforge.org/netperf/netperf-2.6.0-1.el6.rf.x8664.rpm" ./build/health-check.install: PACKAGES="$PACKAGES python-psutil http://pkgs.repoforge.org/fio/fio-2.1.7-1.el6.rf.x8664.rpm http://pkgs.repoforge.org/lshw/lshw-2.17-1.el6.rf.x8664.rpm" ./build/health-check.install: PACKAGES="$PACKAGES http://pkgs.repoforge.org/fio/fio-2.1.7-1.el7.rf.x8664.rpm http://pkgs.repoforge.org/lshw/lshw-2.17-1.el7.rf.x8664.rpm" ./build/init: curl -s -S -o/configure -F section=${SECTION} -F file=@/hw.json http://${SERV}:${HTTPPORT}/${HTTPPATH}/upload.py & ./build/init: giveup "Curl exited as failed ($RETCODE). Cannot get a configuration from http://${SERV}:${HTTPPORT}/${HTTPPATH}/upload.py'" ./build/init: log "Transferring files from http://${HSERV}:${HSERVPORT}/${HPATH}/${VERS}/${ROLE}-${VERS}.edeploy..." ./build/init: curl -s -S http://${HSERV}:${HSERVPORT}/${HPATH}/${VERS}/${ROLE}-${VERS}.edeploy | gzip -d | tar x --xattrs --selinux -C $d || giveup "Unable to download http://${HSERV}:${HSERVPORT}/${HPATH}/${VERS}/${ROLE}-${VERS}.edeploy" ./build/init.common: curl http://169.254.169.254/2009-04-04/user-data -fso /user-data -m 5 --retry 10 --retry-delay 2 ./build/init.common: curl -s -S -o/log.stats -F section=${SECTION} -F file=@/${logfile} http://${SERV}:${HTTPPORT}/${HTTPPATH}/upload.py || : ./build/init.common: curl -s -S -F section=${SECTION} -F failure=$PROFILE -F file=@/hw.json http://${SERV}:${HTTPPORT}/${HTTPPATH}/upload.py ./build/init.health:curl -s -S $SESSIONCURL -F file=@/health.json http://${SERV}:${HTTPPORT}/${HTTPPATH}/upload-health.py & ./build/init.health: log "Curl exited as failed ($RETCODE). Cannot get a configuration from http://${SERV}:${HTTPPORT}/${HTTPPATH}/upload-health.py'" ./build/pxe.install: PACKAGES="$PACKAGES http://pkgs.repoforge.org/lshw/lshw-2.17-1.el6.rf.x8664.rpm" ./build/repositories: echo "http://http.debian.net/debian" ./build/repositories: echo "http://archive.ubuntu.com/ubuntu" ./build/repositories: echo "http://mirror.centos.org/centos/6.5/os/x8664/Packages/centos-release-6-5.el6.centos.11.1.x8664.rpm" ./build/repositories: echo "http://mirror.centos.org/centos/7/os/x8664/Packages/centos-release-7-0.1406.el7.centos.2.3.x8664.rpm" ./build/repositories: wget "http://dev.centos.org/centos/6/SCL/scl.repo" -O $dir/etc/yum.repos.d/scl.repo Binary file ./build/sources/lshw matches ./server/edeploy.conf:PXEMNGRURL=http://192.168.122.1:8000/ ./server/upload-health.py:$ curl -i -F name=test -F file=@/tmp/hw.lst http://localhost/cgi-bin/upload.py ./server/upload.py:$ curl -i -F name=test -F file=@/tmp/hw.lst http://localhost/cgi-bin/upload.py ./setup.cfg:home-page = http://www.enovance.com/ ./src/sampledmesg: Command line: BOOTIMAGE=vmlinuz initrd=http://10.101.14.14/health.pxe DEBUG=1 SERV=10.101.14.14 HSERV=10.101.14.14 UPLOADLOG=1 IP=all:dhcp SESSION=smoke NONETWORKTEST=1 ONSUCCESS=console ONFAILURE=console |pci=bfsort| ./src/sampledmesg: Kernel command line: BOOTIMAGE=vmlinuz initrd=http://10.101.14.14/health.pxe DEBUG=1 SERV=10.101.14.14 HSERV=10.101.14.14 UPLOADLOG=1 IP=all:dhcp SESSION=smoke NONETWORKTEST=1 ONSUCCESS=console ONFAILURE=console |pci=bfsort|
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8174?
CVE-2014-8174 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2014-8174?
To fix CVE-2014-8174, upgrade to the latest version of eDeploy that addresses this vulnerability.
What type of attacks can be executed with CVE-2014-8174?
CVE-2014-8174 allows remote attackers to execute arbitrary code by exploiting the way sensitive files are downloaded via HTTP.
Which versions of eDeploy are affected by CVE-2014-8174?
CVE-2014-8174 affects eDeploy versions up to and including 1.11.0.
Is there any workaround for CVE-2014-8174 before applying the fix?
A potential workaround for CVE-2014-8174 is to restrict HTTP access or monitor downloads while a fixed version is being deployed.