CVE-2018-1127
published 2018-09-11CVE-2018-1127: Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Session tokens remain active for a few…
PriorityP337high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
1.26%
66.4th percentile
Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Session tokens remain active for a few minutes allowing attackers to replay tokens acquired via sniffing/MITM attacks and authenticate as the target user.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | red_hat_gluster_storage | — | — |
| redhat | gluster_storage | < 3.4 | 3.4 |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tendrl-api: Improper cleanup of session token can allow attackers to hijack user sessions
vendor_redhat·2018-05-08·CVSS 4.2
CVE-2018-1127 [MEDIUM] CWE-613 tendrl-api: Improper cleanup of session token can allow attackers to hijack user sessions
tendrl-api: Improper cleanup of session token can allow attackers to hijack user sessions
Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Session tokens remain active for a few minutes allowing attackers to replay tokens acquired via sniffing/MITM attacks and authenticate as the target user.
GHSA
GHSA-jwq3-h8rx-wcwj: Tendrl API in Red Hat Gluster Storage before 3
ghsa_unreviewed·2022-05-13
CVE-2018-1127 [HIGH] CWE-384 GHSA-jwq3-h8rx-wcwj: Tendrl API in Red Hat Gluster Storage before 3
Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Session tokens remain active for a few minutes allowing attackers to replay tokens acquired via sniffing/MITM attacks and authenticate as the target user.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16376 openjpeg: Heap-based buffer overflow in function t2_encode_packet in src/lib/openmj2/t2.c
bugzilla·2018-09-06·CVSS 8.8
CVE-2018-16376 [HIGH] CVE-2018-16376 openjpeg: Heap-based buffer overflow in function t2_encode_packet in src/lib/openmj2/t2.c
CVE-2018-16376 openjpeg: Heap-based buffer overflow in function t2_encode_packet in src/lib/openmj2/t2.c
An issue was discovered in OpenJPEG 2.3.0. A heap-based buffer overflow was discovered in the function t2_encode_packet in lib/openmj2/t2.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact.
Upstream bug:
https://github.com/uclouvain/openjpeg/issues/1127
Discussion:
Upstream issue: https://github.com/uclouvain/openjpeg/issues/992
Patch: https://github.com/uclouvain/openjpeg/commit/c535531f03369623b9b833ef41952c62257b507e
Upstream reproducer: https://github.com/asarubbo/poc/blob/master/00322-openjpeg-heapoverflow-opj_t2_encode_packet
---
Analysis:
This is the classic case in which the length of the ar
Bugzilla
CVE-2018-1127 tendrl-api: Improper cleanup of session token can allow attackers to hijack user sessions
bugzilla·2018-05-08·CVSS 4.2
CVE-2018-1127 [MEDIUM] CVE-2018-1127 tendrl-api: Improper cleanup of session token can allow attackers to hijack user sessions
CVE-2018-1127 tendrl-api: Improper cleanup of session token can allow attackers to hijack user sessions
Tendrl API in Red Hat Gluster Storage does not immediately remove session tokens after a user logs out. Session tokens remain active for a few minutes allowing attackers to replay tokens acquired via sniffing/MITM attacks and authenticate as the target user.
Upstream patch:
https://github.com/Tendrl/api/pull/422
Discussion:
Acknowledgments:
Name: Filip Balák (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Gluster Storage 3.4 for RHEL 7
Via RHSA-2018:2616 https://access.redhat.com/errata/RHSA-2018:2616
http://www.securitytracker.com/id/1041597https://access.redhat.com/errata/RHSA-2018:2616https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1127https://github.com/Tendrl/api/pull/422http://www.securitytracker.com/id/1041597https://access.redhat.com/errata/RHSA-2018:2616https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1127https://github.com/Tendrl/api/pull/422
2018-09-11
Published