Vulnerability: Unauthorized Access to GlusterFS StorageClass in OpenShift Container Platform

Vulnerability: Unauthorized Access to GlusterFS StorageClass in OpenShift Container Platform

CVE-2019-10225 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions is able to obtain the value of restuserkey, and use it to authenticate to the GlusterFS REST service, gaining access to read, and modify files.

Learn more about our User Device Pen Test.