Lucene search

K
redhatcveRedhat.comRH:CVE-2018-10930
HistoryOct 09, 2019 - 10:51 p.m.

CVE-2018-10930

2019-10-0922:51:17
redhat.com
access.redhat.com
12

0.001 Low

EPSS

Percentile

39.4%

A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume.

Mitigation

To limit exposure of gluster server nodes :

1. gluster server should be on LAN and not reachable from public networks.
2. Use gluster auth.allow and auth.reject.
3. Use TLS certificates to authenticate gluster clients.

caveat: This does not protect from attacks by authenticated gluster clients.