+1
Hi all,
A network security audit on a customer infrastructure reported a vulnerability on the cerebro http (port 2020) who is open on http in every CVM and without any security prompt.
Some sensitives informations are visible :
- AOS version : el7.3-release-euphrates-5.10.7-stable-...
- VM Names
- Protection Domain names
- Witness ip address
- ...
Is there’s a way to secure this component ?
icon
Best answer by sbarab 27 November 2019, 17:54
@frederic_es So I checked further. Presently there is plan to provide further security for this port on future release of AOS (probably AOS 5.18, but this can be changed) , but one thing to note is that this port can only be accessed from the network of the cluster or the remote site, it is not available for any other networks, you will get permission denied.Let me know if you have further concerns.
View original