OSSN-0014: Multiple Cinder drivers set insecure file permissions

Summary

Several Cinder volume drivers set insecure file permissions for various files and directories. These permissions render the files accessible for read and write to any user with access to the Cinder host as well as any processes running on it. This exposes user block storage data to potential disclosure, corruption, or destruction.

Affected Services / Software

Cinder, Folsom, Grizzly, Havana, Icehouse

Discussion

Several Cinder drivers set file permissions that allow read and write access to ‘group’ and ‘others’. Affected drivers include:

  • GPFS

  • GlusterFS

  • Huawei

  • NetApp/NFS

  • Nexenta

  • NFS

  • Scality

Essentially, user volumes are made accessible to all who have access to the Cinder host. Daemons running on the host are also able to access the affected user volumes. The relaxed file permissions can be exploited to disclose, modify, corrupt, or destroy user volume data.

All versions of Cinder are vulnerable in Icehouse and earlier releases with a single exception: systems using the Icehouse GPFS driver.

This issue was reported by Dirk Mueller of SUSE.

Contacts / References

Author: Nathan Kinder, Red Hat