First published: Thu Dec 17 2020(Updated: )
Red Hat Gluster Storage is software only scale-out storage solution that<br>provides flexible and affordable unstructured data storage. It unifies data<br>storage and infrastructure, increases performance, and improves<br>availability and manageability to meet enterprise-level storage challenges.<br>Security Fix(es):<br><li> grafana: SSRF incorrect access control vulnerability allows unauthenticated users to make grafana send HTTP requests to any URL (CVE-2020-13379)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>This advisory fixes the following bug:<br><li> Previously, tendrl-node-agent service was unable to import the cluster in a VMware environment as tendrl was looking for the serial number of the devices. With the current update, tendrl-node-agent service is able to import the cluster in a VMware environment without failure as the hardware_id and parent_id of the devices are used after proper validation instead of the serial number. (BZ#1809920)</li> Users of web-admin-build with Red Hat Gluster Storage are advised to upgrade to these updated packages.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/tendrl-node-agent | <1.6.3-20.el7 | 1.6.3-20.el7 |
redhat/grafana | <5.2.4-3.el7 | 5.2.4-3.el7 |
redhat/python-django | <1.11.27-1.el7 | 1.11.27-1.el7 |
redhat/tendrl-monitoring-integration | <1.6.3-23.el7 | 1.6.3-23.el7 |
redhat/python-django-bash-completion | <1.11.27-1.el7 | 1.11.27-1.el7 |
redhat/python2-django | <1.11.27-1.el7 | 1.11.27-1.el7 |
redhat/python2-django-doc | <1.11.27-1.el7 | 1.11.27-1.el7 |
redhat/tendrl-grafana-plugins | <1.6.3-23.el7 | 1.6.3-23.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2020:5599 is classified as important.
To fix RHSA-2020:5599, upgrade the affected packages to their respective remedied versions listed in the advisory.
RHSA-2020:5599 affects several packages including tendrl-node-agent, grafana, and python-django among others.
You need to upgrade to the specified versions such as tendrl-node-agent 1.6.3-20.el7 and grafana 5.2.4-3.el7 as indicated in the advisory.
Yes, RHSA-2020:5599 involves vulnerabilities affecting Red Hat Gluster Storage, which is a software-defined storage solution.