REDHAT-BUG-1558721: High severity gluster Gluster vulnerability
As reported:
When certain options are enabled in Gluster, it creates a volume called glustersharedstorage. This volume is mounted on each server in the cluster and used to share state. The volume is not intended to be mounted by storage clients as it does not contain any data that is intended to be user accessi= ble. When snapshot scheduling is enabled in Gluster, this glustersharedstorage volume is used to coordinate the snapshots. Part of that is sharing the cron job that is used to trigger scheduled snaps. The crontab file exposed in the shared volume is symlinked into each server's /etc/cron.d directory. By default, the sharedstorage volume can be mounted by any client that has access to the cluster to mount data volumes. Further, since Gluster relies = on client-reported uids, the sharedstorage volume can be written from any of these clients, permitting cron entries to be added to the system crontab directory such that they will be executed by each server as root (or any ot= her uid).
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1558721?
The vulnerability REDHAT-BUG-1558721 has a moderate severity level due to potential exploitation risks to shared state.
How do I fix REDHAT-BUG-1558721?
To fix REDHAT-BUG-1558721, ensure that the gluster_shared_storage volume is not mounted by storage clients and review the configuration settings.
What software is affected by REDHAT-BUG-1558721?
The affected software for REDHAT-BUG-1558721 is Gluster, specifically when certain options are enabled.
Can REDHAT-BUG-1558721 lead to data exposure?
Yes, REDHAT-BUG-1558721 can lead to data exposure if the gluster_shared_storage volume is improperly accessed.
Is there a workaround for REDHAT-BUG-1558721?
A workaround for REDHAT-BUG-1558721 is to restrict access to the gluster_shared_storage volume to prevent client mounting.