CVE-2018-1127: Red Hat Gluster Storage

High severity, CVSS 8.1. EPSS: 1.3% chance of exploitation in the next 30 days.

Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Session tokens remain active for a few minutes allowing attackers to replay tokens acquired via sniffing/MITM attacks and authenticate as the target user.

Affected products

  • Red Hat Gluster Storage: before 3.4 (fixed in 3.4)

Published 2018-09-11. Last modified 2026-06-17.