Medium severity4.2NVD Advisory· Published Sep 11, 2018· Updated Jun 17, 2026
CVE-2018-1127
CVE-2018-1127
Description
Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Session tokens remain active for a few minutes allowing attackers to replay tokens acquired via sniffing/MITM attacks and authenticate as the target user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<3.4.0+ 1 more
- (no CPE)range: <3.4.0
- (no CPE)range: 3.4.0
Patches
Vulnerability mechanics
References
4- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchVendor Advisory
- github.com/Tendrl/api/pull/422nvdPatchThird Party Advisory
- www.securitytracker.com/id/1041597nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2018:2616nvdVendor Advisory
News mentions
0No linked articles in our index yet.