Database/Control plane, storage & DevOps
GlusterFS (glusterd management): MULTI-TENANT ISOLATION: an authenticated TLS client can use gluster cli --remote-host
Impact
MULTI-TENANT ISOLATION: an authenticated TLS client can use gluster cli --remote-host to add itself to the trusted storage pool, at which point it runs privileged management operations. A tenant with a client certificate becomes a storage administrator and can reconfigure or destroy other tenants' volumes.
Who can reach it
Any client holding a valid TLS credential that can reach glusterd on a server node.
What to do
Upgrade glusterfs and restart glusterd on every server. Separate the management network from the client data network so tenant nodes cannot reach glusterd's management port at all, and review the trusted pool membership for hosts you did not add.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.