Back

MEDIUM

atomic-openshift: The basic-user RBAC role allow leaking of GlusterFS StorageClass restuserkey value

Published Mar 19, 2021

Description

A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions is able to obtain the value of restuserkey, and use it to authenticate to the GlusterFS REST service, gaining access to read, and modify files.

Affected products

Remediation

Red Hat mitigation

Use of the restuserkey in GlusterFS StorageClass is deprecated upstream [1] and will be removed in a future release. To mitigate this vulnerability make use of secretName, and secretNamespace parameters to store the Gluster REST service password. [1] https://kubernetes.io/docs/concepts/storage/storage-classes/#glusterfs

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Mar 19, 2021
Updated Aug 4, 2024
Reserved Mar 27, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Aug 19, 2019
Bugzilla 1743073

ENISA EUVD

Assigner redhat
Published Mar 19, 2021
Updated Aug 4, 2024

GitHub

No data