It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of these flaws to execute arbitrary code, create arbitrary files, or cause denial of service on glusterfs server nodes via symlinks to relative paths.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade glusterfs-server | Aug 28, 2019 | Oct 31, 2018 |
| Debian | — | Upgrade glusterfs | Feb 19, 2019 | Oct 31, 2018 |
| Gentoo Linux | — | Upgrade sys-cluster/glusterfs. | Apr 3, 2019 | Oct 31, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade glusterfs-cliUpgrade glusterfsUpgrade glusterfs-libsUpgrade glusterfs-rdmaUpgrade glusterfs-fuseUpgrade glusterfs-develUpgrade glusterfs-client-xlatorsUpgrade glusterfs-api-develUpgrade glusterfs-extra-xlatorsUpgrade glusterfs-apiUpgrade python2-glusterUpgrade glusterfs-server | Aug 31, 2020 | Oct 31, 2018 |
| Redhat_linux | — | Upgrade glusterfs-server | Jun 14, 2019 | Oct 31, 2018 |
| Ubuntu | — | Upgrade glusterfs-client (Ubuntu Pro)Upgrade glusterfs-server (Ubuntu Pro)Upgrade glusterfs-common (Ubuntu Pro) | Mar 22, 2023 | Oct 31, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub