Database/Control plane, storage & DevOps
GlusterFS (glusterd, auth.allow): The auth.allow option does not actually restrict who may connect, so any
Impact
The auth.allow option does not actually restrict who may connect, so any unauthenticated gluster client on any network mounts the volume. Every dataset and checkpoint on that volume is readable and writable by anyone who can reach the bricks.
Who can reach it
Any host with network reach to glusterd/brick ports. No credential and no membership in the trusted pool required.
What to do
Upgrade glusterfs server to 3.10.12 / 4.0.2 or later and restart glusterd and the brick processes. Do not rely on auth.allow as the boundary - enforce TLS with client certificates (transport.socket.ssl) and firewall brick ports to known client subnets.
References
Related entries
- Altair PBS Professional / OpenPBS (pbs_mom): Pbs_mom, the daemon that executes jobs on every compute node, acceptsCVE-2019-15719 · Altair PBS Professional / OpenPBS (pbs_mom)High
- Ceph MON / MGR (ceph-mon, ceph-mgr): Ceph-mon and ceph-mgr fail to enforce the caps on an authenticated principal, so aCVE-2020-10736 · Ceph MON / MGR (ceph-mon, ceph-mgr)High
- Eaton Intelligent Power Manager (IPM) prior to 1.69 - meta_driver_srv.js: Unauthenticated arbitrary file deletionCVE-2021-23279 · Eaton Intelligent Power Manager (IPM) prior to 1.69 - meta_driver_srv.jsHigh
- Intel Data Center Manager: Improper neutralisation (injection) in Data Center Manager lets an authenticated userCVE-2022-21225 · Intel Data Center ManagerHigh
- Schneider Electric Data Center Expert (versions prior to v7.9.0) - credential storage: DCE stores device passwordsCVE-2022-32519 · Schneider Electric Data Center Expert (versions prior to v7.9.0) - credential storageHigh
- Intel Neural Compressor (SQL injection): SQL injection reachable by an authenticated user of Neural CompressorCVE-2024-39368 · Intel Neural Compressor (SQL injection)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.