CVE-2018-10841Authentication Bypass Using an Alternate Path or Channel in Glusterfs

Severity
8.8HIGHNVD
EPSS
0.7%
top 28.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 20
Latest updateMay 13

Description

glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privileged gluster operations like adding other machines to trusted storage pool, start, stop, and delete volumes.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDgluster/glusterfs< 4.1.8
Debiangluster/glusterfs< 4.1.2-1+3
CVEListV5red_hat/glusterfsall

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-383h-f6wm-hpxc: glusterfs is vulnerable to privilege escalation on gluster server nodes2022-05-13
OSV
glusterfs vulnerabilities2021-03-15
OSV
CVE-2018-10841: glusterfs is vulnerable to privilege escalation on gluster server nodes2018-06-20
CVEList
CVE-2018-10841: glusterfs is vulnerable to privilege escalation on gluster server nodes2018-06-20

📋Vendor Advisories

3
Ubuntu
GlusterFS vulnerabilities2021-03-15
Red Hat
glusterfs: access trusted peer group via remote-host command2018-06-20
Debian
CVE-2018-10841: glusterfs - glusterfs is vulnerable to privilege escalation on gluster server nodes. An auth...2018

💬Community

6
Bugzilla
CVE-2018-10841 glusterfs: access trusted peer group via remote-host command [glusterfs upstream]2018-06-21
Bugzilla
CVE-2018-10841 glusterfs: access trusted peer group via remote-host command [glusterfs upstream]2018-06-21
Bugzilla
CVE-2018-10841 glusterfs: access trusted peer group via remote-host command [epel-all]2018-06-20
Bugzilla
CVE-2018-10841 glusterfs: access trusted peer group via remote-host command [fedora-all]2018-06-20
Bugzilla
CVE-2018-10841 glusterfs: access trusted peer group via remote-host command [glusterfs upstream]2018-06-20
CVE-2018-10841 — Gluster Glusterfs vulnerability | cvebase