Back

HIGH

glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression)

Published Apr 25, 2018

Description

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

Affected products

Remediation

Red Hat statement

This vulnerability affects gluster servers that use 'auth.allow' to restrict access to gluster volumes. Gluster servers using TLS to authenticate gluster clients are not affected by this. This vulnerability allows any client to connect to any gluster volume which only uses auth.allow to restrict access. This issue did not affect the versions of glusterfs as shipped with Red Hat Enterprise Linux 6 and 7 because only gluster client is shipped in these products. CVE-2018-1112 affects glusterfs-server package as shipped with Red Hat Gluster Storage 3.

Red Hat mitigation

1. Use TLS Authentication to authenticate gluster clients to limit access to gluster storage volumes 2. The gluster server should be on LAN, firewalled to trusted systems, and not reachable from public networks.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 25, 2018
Updated Aug 5, 2024
Reserved Dec 4, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Apr 19, 2018