Hi all,

I came across this blog entry. It seems that there's an undocumented
command line option that allows someone to execute a gluster cli command on
a remote host.

https://joejulian.name/blog/one-more-reason-that-glusterfs-should-not-be-used-as-a-saas-offering/

I am on gluster 3.9 and the option is still supported. I'd really like to
understand why this option is still supported and what someone could do to
actually mitigate this vulnerability.  Is there some configuration option I
can set to turn this off for example?

Thanks,
Joe
_______________________________________________
Gluster-users mailing list
Gluster-users@gluster.org
http://lists.gluster.org/mailman/listinfo/gluster-users

Reply via email to