Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2021-36780: Unauthorized data access from replicas through vulnerable instance manager pods #3420

Closed
innobead opened this issue Dec 16, 2021 · 0 comments
Assignees
Labels
area/security System or volume data access security backport/1.1.3 Require to backport to 1.1.3 release branch kind/bug
Milestone

Comments

@innobead
Copy link
Member

innobead commented Dec 16, 2021

The Longhorn instance manager pods are responsible for volume replica management and access. The vulnerability issue is found that it is possible to connect to a longhorn-engine replica instance running in the instance-manager replica pod. The longhorn-engine replica can handle multiple TCP connections. Each connection is able to read and write data on the replica. It may allow other pods in the cluster to read and write data to and from a replica that the malicious pod doesn't have access to.

@innobead innobead added kind/bug backport/1.1.3 Require to backport to 1.1.3 release branch labels Dec 16, 2021
@innobead innobead added this to the v1.2.3 milestone Dec 16, 2021
@innobead innobead changed the title [BUG] CVE-2021-36780: Unauthorized data access from replicas through vulnerable instance manager pods Dec 17, 2021
@joshimoo joshimoo added the area/security System or volume data access security label Dec 17, 2021
@derekbit derekbit moved this to Closed in Longhorn Sprint Aug 3, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/security System or volume data access security backport/1.1.3 Require to backport to 1.1.3 release branch kind/bug
Projects
Status: Closed
Development

No branches or pull requests

3 participants