CVE-2018-10928

CWE-5911 documents8 sources
Severity
8.8HIGH
EPSS
1.7%
top 17.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 4
Latest updateMay 13

Description

A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages7 packages

NVDgluster/glusterfs3.123.12.14+1
Debianglusterfs< 4.1.4-1+3
CVEListV5red_hat/glusterfsn/a

Also affects: Debian Linux 8.0, 9.0, Enterprise Linux 6.0, 7.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-884c-j6hw-f37p: A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the glu2022-05-13
OSV
CVE-2018-10928: A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the glu2018-09-04
CVEList
CVE-2018-10928: A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the glu2018-09-04

📋Vendor Advisories

4
Ubuntu
GlusterFS vulnerabilities2021-03-15
Red Hat
glusterfs: glusterfs server exploitable via symlinks to relative paths2018-10-31
Red Hat
glusterfs: Improper resolution of symlinks allows for privilege escalation2018-09-04
Debian
CVE-2018-10928: glusterfs - A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which...2018

💬Community

3
Bugzilla
CVE-2018-14651 glusterfs: glusterfs server exploitable via symlinks to relative paths2018-09-25
Bugzilla
CVE-2018-10928 glusterfs: Improper resolution of symlinks allows for privilege escalation [fedora-all]2018-09-04
Bugzilla
CVE-2018-10928 glusterfs: Improper resolution of symlinks allows for privilege escalation2018-08-06