Heketi is used to manage GlusterFS nodes and volumes. The default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse.
A flaw was found in heketi API that permits issuing of OS commands through especially crafted requests, possibly leading to escalation of privileges.
https://github.com/heketi/heketi/releases/tag/v5.0.1 https://github.com/heketi/heketi/commit/787bae461b23003a4daa4d1d639016a754cf6b00
https://access.redhat.com/security/vulnerabilities/3246991
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.