← Back

CVE-2018-10928

nvd nist
Published: Sep 4, 2018Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.

Affected (11)

Show all products
1 product
Debian Linux
4 products
Enterprise Linux
Enterprise Linux Server
Gluster Storage
Virtualization Host
1 product
Glusterfs
1 product
Leap
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 8.0
Version 9.0
Redhat
Version 6.0
Version 7.0
Redhat
Version 6.0
Version 7.0
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Gluster
From 3.12 to 3.12.14
From 4.1 to 4.1.8
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.0
Version 4.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.1

References (16)

Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.