Bug 1850077
Summary: | targetcli: weak permissions config files | |||
---|---|---|---|---|
Product: | [Red Hat Storage] Red Hat Gluster Storage | Reporter: | Prasanna Kumar Kalever <prasanna.kalever> | |
Component: | gluster-block | Assignee: | Prasanna Kumar Kalever <prasanna.kalever> | |
Status: | CLOSED ERRATA | QA Contact: | Sayalee <saraut> | |
Severity: | high | Docs Contact: | ||
Priority: | unspecified | |||
Version: | ocs-3.11 | CC: | dwalveka, pprakash, prasanna.kalever, puebele, rhs-bugs, sabose, saraut, xiubli | |
Target Milestone: | --- | Keywords: | ZStream | |
Target Release: | OCS 3.11.z Async | |||
Hardware: | Unspecified | |||
OS: | Unspecified | |||
Whiteboard: | ||||
Fixed In Version: | gluster-block-0.2.1-36.1.el7rhgs | Doc Type: | Bug Fix | |
Doc Text: |
An access flaw CVE-2020-13867 was found in targetcli due to which the files under ‘/etc/target’ and '/etc/target/backup' directory were widely accessible. With this release, the access flaw is fixed as a workaround in gluster-block to protect these files from any potential attacks for accessing sensitive information, at least until the flaw is resolved and made available in targetcli.
|
Story Points: | --- | |
Clone Of: | ||||
: | 1877227 (view as bug list) | Environment: | ||
Last Closed: | 2020-09-30 15:17:24 UTC | Type: | --- | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Embargoed: | ||||
Bug Depends On: | ||||
Bug Blocks: | 1877227 |
Comment 13
errata-xmlrpc
2020-09-30 15:17:24 UTC
|