CVE-2018-1127: High severity red hat gluster storage vulnerability
Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Session tokens remain active for a few minutes allowing attackers to replay tokens acquired via sniffing/MITM attacks and authenticate as the target user.
Other sources
Tendrl API in Red Hat Gluster Storage does not immediately remove session tokens after a user logs out. Session tokens remain active for a few minutes allowing attackers to replay tokens acquired via sniffing/MITM attacks and authenticate as the target user.
Upstream patch:
https://github.com/Tendrl/api/pull/422
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-1127.
What is the severity of CVE-2018-1127?
The severity of CVE-2018-1127 is high (8.1).
How does this vulnerability affect Red Hat Gluster Storage?
This vulnerability affects Red Hat Gluster Storage versions up to (but not including) 3.4.0.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by sniffing/MITM attacks to acquire session tokens and authenticate as the target user.
Is there a fix available for CVE-2018-1127?
Yes, a fix for CVE-2018-1127 is available in Red Hat Gluster Storage version 3.4.0.