It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2017:3110 | vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15087 | issue tracking vendor advisory |
http://www.securityfocus.com/bid/101556 | vdb entry third party advisory |