Lucene search

K
redhatcveRedhat.comRH:CVE-2018-1112
HistoryApr 24, 2018 - 2:48 p.m.

CVE-2018-1112

2018-04-2414:48:41
redhat.com
access.redhat.com
10

EPSS

0.008

Percentile

81.9%

It was found that fix for CVE-2018-1088 introduced a new vulnerability in the way ‘auth.allow’ is implemented in glusterfs server. An unauthenticated gluster client could mount gluster storage volumes.

Mitigation

1. Use TLS Authentication to authenticate gluster clients to limit access to gluster storage volumes

2. The gluster server should be on LAN, firewalled to trusted systems, and not reachable from public networks.