REDHAT-BUG-1631576: Medium severity gluster Gluster file system vulnerability
The Gluster file system through version 4.1.4 is vulnerable to abuse of the "features/index" translator. A remote attacker with access to mount volumes could exploit this via the "GFXATTROPENTRYINKEY" xattrop to create arbitrary, empty files on the target server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1631576?
The vulnerability REDHAT-BUG-1631576 is classified as high severity due to the potential for remote attackers to create arbitrary, empty files.
How do I fix REDHAT-BUG-1631576?
To fix REDHAT-BUG-1631576, upgrade the Gluster file system to version 4.1.5 or later to mitigate the vulnerability.
What is the impact of REDHAT-BUG-1631576?
The impact of REDHAT-BUG-1631576 allows a remote attacker to exploit the system and create arbitrary files, leading to possible data manipulation.
Who is affected by REDHAT-BUG-1631576?
The vulnerability REDHAT-BUG-1631576 affects all users of the Gluster file system versions prior to 4.1.5.
What component of Gluster is affected in REDHAT-BUG-1631576?
The component affected in REDHAT-BUG-1631576 is the 'features/index' translator used in the Gluster file system.