Session Token Vulnerability in Red Hat Gluster Storage by Red Hat
CVE-2018-1127
4.2MEDIUM
What is CVE-2018-1127?
The Tendrl API in Red Hat Gluster Storage prior to version 3.4.0 exhibits a significant session management flaw where session tokens are not promptly invalidated after user logout. This weakness allows an attacker who has intercepted or acquired session tokens through methods such as sniffing or man-in-the-middle attacks to retain access to the user’s session for a few minutes, thereby facilitating unauthorized authentication as the targeted user.
Affected Version(s)
Red Hat Gluster Storage 3.4.0