GPU VulnDB

Database/Control plane, storage & DevOps

GlusterFS (glusterd management): MULTI-TENANT ISOLATION: an authenticated TLS client can use gluster cli --remote-host

CVE-2018-10841Control plane, storage & DevOpscurated

Impact

MULTI-TENANT ISOLATION: an authenticated TLS client can use gluster cli --remote-host to add itself to the trusted storage pool, at which point it runs privileged management operations. A tenant with a client certificate becomes a storage administrator and can reconfigure or destroy other tenants' volumes.

Who can reach it

Any client holding a valid TLS credential that can reach glusterd on a server node.

What to do

Upgrade glusterfs and restart glusterd on every server. Separate the management network from the client data network so tenant nodes cannot reach glusterd's management port at all, and review the trusted pool membership for hosts you did not add.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.