Database/Control plane, storage & DevOps
GlusterFS (glusterd management): An authenticated TLS client can use gluster cli --remote-host to add itself to the
Impact
An authenticated TLS client can use gluster cli --remote-host to add itself to the trusted storage pool, at which point it runs privileged management operations. A tenant with a client certificate becomes a storage administrator and can reconfigure or destroy other tenants' volumes.
Who can reach it
Any client holding a valid TLS credential that can reach glusterd on a server node.
What to do
Upgrade glusterfs and restart glusterd on every server. Separate the management network from the client data network so tenant nodes cannot reach glusterd's management port at all, and review the trusted pool membership for hosts you did not add.
References
Related entries
- Intel SPS (HECI subsystem compartmentalisation): Insufficient compartmentalisation in the HECI interfaceCVE-2021-0060 · Intel SPS (HECI subsystem compartmentalisation)Medium
- Dell CloudLink (cluster component exception handling): A highly privileged remote attacker performs unauthorizedCVE-2024-38482 · Dell CloudLink (cluster component exception handling)Medium
- AMD Versal Adaptive SoC - PLM runtime services address validation: The Platform Loader and Manager firmware on AMDCVE-2025-0037 · AMD Versal Adaptive SoC - PLM runtime services address validationMedium
- Ansible automation-controller: unvalidated system-job "days" value injects arguments into control-node awx-manageCVE-2026-84724 · Red Hat Ansible Automation Platform automation-controller (system-job launch, awx-manage argument vector)Medium
- HTCondor (condor_schedd, GSI/VOMS extension parsing): An authenticated user crashes the schedd by feeding it malformedCVE-2017-16816 · HTCondor (condor_schedd, GSI/VOMS extension parsing)Medium
- GlusterFS (dict_unserialize): A negative key length in a serialized dict makes the server read memory from elsewhere inCVE-2018-10911 · GlusterFS (dict_unserialize)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.