Heketi is used to manage GlusterFS nodes and volumes. The default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse.
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
A flaw was found in heketi API that permits issuing of OS commands through especially crafted requests, possibly leading to escalation of privileges.
https://github.com/heketi/heketi/releases/tag/v5.0.1 https://github.com/heketi/heketi/commit/787bae461b23003a4daa4d1d639016a754cf6b00
https://access.redhat.com/security/vulnerabilities/3246991