For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
Red Hat Gluster Storage is software only scale-out storage solution that
provides flexible and affordable unstructured data storage. It unifies data
storage and infrastructure, increases performance, and improves
availability and manageability to meet enterprise-level storage challenges.
Security Fix(es):
* grafana: SSRF incorrect access control vulnerability allows
unauthenticated users to make grafana send HTTP requests to any URL
(CVE-2020-13379)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
This advisory fixes the following bug:
* Previously, tendrl-node-agent service was unable to import the cluster in
a VMware environment as tendrl was looking for the serial number of the
devices. With the current update, tendrl-node-agent service is able to
import the cluster in a VMware environment without failure as the
hardware_id and parent_id of the devices are used after proper validation
instead of the serial number. (BZ#1809920)
Users of web-admin-build with Red Hat Gluster Storage are advised to
upgrade to these updated packages.
https://access.redhat.com/security/cve/CVE-2020-13379 https://access.redhat.com/security/updates/classification/#important
Red Hat Gluster 3.5 Web Administration Node Agent on RHEL-7:
Source:
tendrl-node-agent-1.6.3-20.el7rhgs.src.rpm
noarch:
tendrl-node-agent-1.6.3-20.el7rhgs.noarch.rpm
Red Hat Gluster 3.5 Web Administration on RHEL-7:
Source:
grafana-5.2.4-3.el7rhgs.src.rpm
python-django-1.11.27-1.el7rhgs.src.rpm
tendrl-monitoring-integration-1.6.3-23.el7rhgs.src.rpm
tendrl-node-agent-1.6.3-20.el7rhgs.src.rpm
noarch:
python-django-bash-completion-1.11.27-1.el7rhgs.noarch.rpm
python2-django-1.11.27-1.el7rhgs.noarch.rpm
python2-django-doc-1.11.27-1.el7rhgs.noarch.rpm
tendrl-grafana-plugins-1.6.3-23.el7rhgs.noarch.rpm
tendrl-monitoring-integration-1.6.3-23.el7rhgs.noarch.rpm
tendrl-node-agent-1.6.3-20.el7rhgs.noarch.rpm
x86_64:
grafana-5.2.4-3.el7rhgs.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
Updated web-admin-build packages that fixes one bug are now available forRed Hat Gluster Storage 3.5 on Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Red Hat Gluster 3.5 Web Administration Node Agent on RHEL-7 - noarch
Red Hat Gluster 3.5 Web Administration on RHEL-7 - noarch, x86_64
1809920 - [TestOnly][RHEL 7 only]QE Web Admin on VMWare platform
1843640 - CVE-2020-13379 grafana: SSRF incorrect access control vulnerability allows unauthenticated users to make grafana send HTTP requests to any URL
Get the latest Linux and open source security news straight to your inbox.