#VU14602 Session hijacking in Red Hat Gluster Storage Web Administration and Red Hat Gluster Storage Server for On-premise - CVE-2018-1127
Published: September 4, 2018 / Updated: September 5, 2018
Red Hat Gluster Storage Web Administration
Red Hat Gluster Storage Server for On-premise
Red Hat Inc.
Description
The vulnerability allows a remote attacker to conduct session fixation attack.
The vulnerability exists due to the 'tendrl-api' component does not properly remove session tokens when the target user logs out. A remote attacker can monitor session tokens can replay the tokens to hijack the target user's session.