CVE-2018-1088
published 2018-04-18CVE-2018-1088: A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster…
PriorityP347high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
5.37%
91.8th percentile
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | glusterfs | < glusterfs 4.0.2-1 (bookworm) | glusterfs 4.0.2-1 (bookworm) |
| debian | glusterfs | — | — |
| gluster | glusterfs | < 3.10.12 | 3.10.12 |
| gluster | glusterfs | — | — |
| gluster | glusterfs | >= 0 < 4.0.2-1 | 4.0.2-1 |
| gluster | glusterfs | >= 0 < 4.0.2-1 | 4.0.2-1 |
| gluster | glusterfs | >= 0 < 4.0.2-1 | 4.0.2-1 |
| gluster | glusterfs | >= 0 < 4.0.2-1 | 4.0.2-1 |
| gluster | glusterfs | >= 0 < 3.4.2-1ubuntu1+esm1 | 3.4.2-1ubuntu1+esm1 |
| gluster | glusterfs | >= 0 < 3.7.6-1ubuntu1+esm1 | 3.7.6-1ubuntu1+esm1 |
| gluster | glusterfs | >= 0 < 3.13.2-1ubuntu1+esm1 | 3.13.2-1ubuntu1+esm1 |
| opensuse | leap | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | gluster_storage | 3.0 – 3.13.2 | — |
| redhat | virtualization | — | — |
| redhat | virtualization_host | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rf3g-r74x-84j6: A privilege escalation flaw was found in gluster 3
ghsa_unreviewed·2022-05-13
CVE-2018-1088 [HIGH] CWE-266 GHSA-rf3g-r74x-84j6: A privilege escalation flaw was found in gluster 3
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
GHSA
GHSA-g75c-rwx3-m2xp: glusterfs server before versions 3
ghsa_unreviewed·2022-05-13·CVSS 8.1
CVE-2018-1112 [HIGH] GHSA-g75c-rwx3-m2xp: glusterfs server before versions 3
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.
OSV
glusterfs vulnerabilities
osv·2021-03-15·CVSS 5.0
CVE-2014-3619 [MEDIUM] glusterfs vulnerabilities
glusterfs vulnerabilities
It was discovered that GlusterFS incorrectly handled network requests. An
attacker could possibly use this issue to cause a denial of service. This issue
only affected Ubuntu 14.04 ESM. (CVE-2014-3619)
It was discovered that GlusterFS incorrectly handled user permissions. An
authenticated attacker could possibly use this to add himself to a trusted
storage pool and perform privileged operations on volumes. This issue only
affected Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-10841)
It was discovered that GlusterFS incorrectly handled mounting gluster
volumes. An attacker could possibly use this issue to also mount shared
gluster volumes and escalate privileges through malicious cronjobs. This
issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2
OSV
CVE-2018-1112: glusterfs server before versions 3
osv·2018-04-25·CVSS 8.1
CVE-2018-1112 [HIGH] CVE-2018-1112: glusterfs server before versions 3
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.
OSV
CVE-2018-1088: A privilege escalation flaw was found in gluster 3
osv·2018-04-18·CVSS 8.1
CVE-2018-1088 [HIGH] CVE-2018-1088: A privilege escalation flaw was found in gluster 3
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
Ubuntu
GlusterFS vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 5.0
CVE-2018-10929 [MEDIUM] GlusterFS vulnerabilities
Title: GlusterFS vulnerabilities
Summary: Several security issues were fixed in GlusterFS.
It was discovered that GlusterFS incorrectly handled network requests. An
attacker could possibly use this issue to cause a denial of service. This issue
only affected Ubuntu 14.04 ESM. (CVE-2014-3619)
It was discovered that GlusterFS incorrectly handled user permissions. An
authenticated attacker could possibly use this to add himself to a trusted
storage pool and perform privileged operations on volumes. This issue only
affected Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-10841)
It was discovered that GlusterFS incorrectly handled mounting gluster
volumes. An attacker could possibly use this issue to also mount shared
gluster volumes and escalate privileges through malicious cronjobs. This
Red Hat
jackson-databind: arbitrary code execution in slf4j-ext class
vendor_redhat·2018-07-27·CVSS 8.1
CVE-2018-14718 [HIGH] CWE-502 jackson-databind: arbitrary code execution in slf4j-ext class
jackson-databind: arbitrary code execution in slf4j-ext class
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
A flaw was discovered in jackson-databind, where it would permit polymorphic deserialization of a malicious object using slf4j classes. An attacker could use this flaw to execute arbitrary code.
Statement: This vulnerability in jackson-databind involves exploiting CVE-2018-1088 against slf4j, which was fixed in Red Hat products through the errata referenced at https://access.redhat.com/security/cve/cve-2018-8088. Applications that link only slf4j versions including that fix are not vulnerable to this vulnerability.
Red Hat Satellite 6 is not aff
Red Hat
glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression)
vendor_redhat·2018-04-19·CVSS 8.1
CVE-2018-1112 [HIGH] CWE-287 glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression)
glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression)
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.
It was found that fix for CVE-2018-1088 introduced a new vulnerability in the way 'auth.allow' is implemented in glusterfs server. An unauthenticated gluster client could mount gluster storage volumes.
Statement: This vulnerability affects gluster servers that use 'auth.allow' to restrict access to gluster volumes. Gluster servers using TLS to authenticate gluster clients are not affected by this. This vulnerabilit
Red Hat
glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled
vendor_redhat·2018-04-18·CVSS 8.1
CVE-2018-1088 [HIGH] CWE-266 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled
glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
A privilege escalation flaw was found in gluster snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
Statement: This vulnerability affects gluster servers that have, or have previously had, Gluster volume snapshot scheduling enabled from the CLI. Red Hat Enterprise Virtualization supports volume snapshot scheduling from the
Debian
CVE-2018-1112: glusterfs - glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.a...
vendor_debian·2018·CVSS 8.1
CVE-2018-1112 [HIGH] CVE-2018-1112: glusterfs - glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.a...
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2018-1088: glusterfs - A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any glu...
vendor_debian·2018·CVSS 8.1
CVE-2018-1088 [HIGH] CVE-2018-1088: glusterfs - A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any glu...
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
Scope: local
bookworm: resolved (fixed in 4.0.2-1)
bullseye: resolved (fixed in 4.0.2-1)
forky: resolved (fixed in 4.0.2-1)
sid: resolved (fixed in 4.0.2-1)
trixie: resolved (fixed in 4.0.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-14718 jackson-databind: arbitrary code execution in slf4j-ext class
bugzilla·2019-01-15·CVSS 8.1
CVE-2018-14718 [HIGH] CVE-2018-14718 jackson-databind: arbitrary code execution in slf4j-ext class
CVE-2018-14718 jackson-databind: arbitrary code execution in slf4j-ext class
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
References:
https://github.com/FasterXML/jackson-databind/issues/2097
https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7
Upstream Patch:
https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44
Discussion:
Created jackson-databind tracking bugs for this issue:
Affects: fedora-all [bug 1666416]
---
Statement:
This vulnerability in jackson-databind involves exploiting CVE-2018-1088 against slf4j, which was fixed in Red Hat products through the errata referenced at https://acce
Bugzilla
CVE-2018-1112 glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression) [fedora-all]
bugzilla·2018-04-24·CVSS 8.1
CVE-2018-1112 [HIGH] CVE-2018-1112 glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression) [fedora-all]
CVE-2018-1112 glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-1112 glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression)
bugzilla·2018-04-23·CVSS 8.1
CVE-2018-1112 [HIGH] CVE-2018-1112 glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression)
CVE-2018-1112 glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression)
The fix for CVE-2018-1088 in glusterfs introduced a new flaw where auth.allow allows all clients to mount volumes.
Discussion:
Upstream Fix(es):
https://review.gluster.org/#/c/19899/1..2
---
External References:
https://access.redhat.com/articles/3422521
---
Mitigation:
1. Use TLS Authentication to authenticate gluster clients to limit access to gluster storage volumes
2. The gluster server should be on LAN, firewalled to trusted systems, and not reachable from public networks.
---
Created glusterfs tracking bugs for this issue:
Affects: fedora-all [bug 1571448]
---
Statement:
This vulnerability affects gluster servers that use 'auth.allow' to restrict acc
Bugzilla
CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled [fedora-all]
bugzilla·2018-04-22·CVSS 8.1
CVE-2018-1088 [HIGH] CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled [fedora-all]
CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled [fedora-all]
REVIEW: https://review.gluster.org/19918 (shared storage: Prevent mounting shared storage from non-trusted client) posted (#1) for review on release-3.12 by Shyamsundar Ranganathan
Discussion:
REVIEW: https://review.gluster.org/19919 (server/auth: add option for strict authentication) posted (#1) for review on release-3.12 by Shyamsundar Ranganathan
---
COMMIT: https://review.gluster.org/19918 committed in release-3.12 by "Shyamsundar Ranganathan" with a commit message- shared storage: Prevent mounting shared storage from non-trusted client
gluster shared storage is a volume used for internal storage for
various features including ganesha, geo-rep, snapshot.
So t
Bugzilla
CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled [fedora-all]
bugzilla·2018-04-22·CVSS 8.1
CVE-2018-1088 [HIGH] CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled [fedora-all]
CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled [fedora-all]
REVIEW: https://review.gluster.org/19916 (shared storage: Prevent mounting shared storage from non-trusted client) posted (#1) for review on release-3.10 by Shyamsundar Ranganathan
Discussion:
REVIEW: https://review.gluster.org/19917 (server/auth: add option for strict authentication) posted (#1) for review on release-3.10 by Shyamsundar Ranganathan
---
COMMIT: https://review.gluster.org/19916 committed in release-3.10 by "Shyamsundar Ranganathan" with a commit message- shared storage: Prevent mounting shared storage from non-trusted client
gluster shared storage is a volume used for internal storage for
various features including ganesha, geo-rep, snapshot.
So t
Bugzilla
CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled [fedora-all]
bugzilla·2018-04-22·CVSS 8.1
CVE-2018-1088 [HIGH] CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled [fedora-all]
CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled [fedora-all]
REVIEW: https://review.gluster.org/19920 (shared storage: Prevent mounting shared storage from non-trusted client) posted (#1) for review on release-4.0 by Shyamsundar Ranganathan
Discussion:
REVIEW: https://review.gluster.org/19921 (server/auth: add option for strict authentication) posted (#1) for review on release-4.0 by Shyamsundar Ranganathan
---
COMMIT: https://review.gluster.org/19920 committed in release-4.0 by "Shyamsundar Ranganathan" with a commit message- shared storage: Prevent mounting shared storage from non-trusted client
gluster shared storage is a volume used for internal storage for
various features including ganesha, geo-rep, snapshot.
So this
Bugzilla
CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled [fedora-all]
bugzilla·2018-04-18·CVSS 8.1
CVE-2018-1088 [HIGH] CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled [fedora-all]
CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: th
Bugzilla
CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled [fedora-all]
bugzilla·2018-04-18·CVSS 8.1
CVE-2018-1088 [HIGH] CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled [fedora-all]
CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled [fedora-all]
filed against mainline, applies to 4.0, 3.12, and 3.10. Please do backports
Discussion:
The patches are already in all the different branches, and also fixed in master.
Bugzilla
CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled
bugzilla·2018-03-20·CVSS 8.1
CVE-2018-1088 [HIGH] CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled
CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled
As reported:
When certain options are enabled in Gluster, it creates a volume called
gluster_shared_storage. This volume is mounted on each server in the cluster
and used to share state. The volume is not intended to be mounted by storage
clients as it does not contain any data that is intended to be user accessi=
ble.
When snapshot scheduling is enabled in Gluster, this gluster_shared_storage
volume is used to coordinate the snapshots. Part of that is sharing the cron
job that is used to trigger scheduled snaps. The crontab file exposed in the
shared volume is symlinked into each server's /etc/cron.d directory.
By default, the shared_storage volume can be mounted by any client
Bugzilla
CVE-2018-7648 openjpeg2: stack buffer overflow in mj2/opj_mj2_extract.c
bugzilla·2018-03-08·CVSS 9.8
CVE-2018-7648 [CRITICAL] CVE-2018-7648 openjpeg2: stack buffer overflow in mj2/opj_mj2_extract.c
CVE-2018-7648 openjpeg2: stack buffer overflow in mj2/opj_mj2_extract.c
An issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0 when the binary is built with -DBUILD_MJ2=On option. The output prefix was not checked for length, which could overflow a buffer, when providing a prefix with 50 or more characters on the command line.
References:
https://github.com/uclouvain/openjpeg/issues/1088
Patch:
https://github.com/kbabioch/openjpeg/commit/6d8c0c06ee32dc03ba80acd48334e98728e56cf5
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.htmlhttps://access.redhat.com/errata/RHSA-2018:1136https://access.redhat.com/errata/RHSA-2018:1137https://access.redhat.com/errata/RHSA-2018:1275https://access.redhat.com/errata/RHSA-2018:1524https://bugzilla.redhat.com/show_bug.cgi?id=1558721https://lists.debian.org/debian-lts-announce/2021/11/msg00000.htmlhttps://security.gentoo.org/glsa/201904-06http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.htmlhttps://access.redhat.com/errata/RHSA-2018:1136https://access.redhat.com/errata/RHSA-2018:1137https://access.redhat.com/errata/RHSA-2018:1275https://access.redhat.com/errata/RHSA-2018:1524https://bugzilla.redhat.com/show_bug.cgi?id=1558721https://lists.debian.org/debian-lts-announce/2021/11/msg00000.htmlhttps://security.gentoo.org/glsa/201904-06
2018-04-18
Published