CVE-2018-1112
published 2018-04-25CVE-2018-1112: glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from…
PriorityP353high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.43%
82.5th percentile
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glusterfs | — | — |
| gluster | glusterfs | < 3.10.12 | 3.10.12 |
| gluster | glusterfs | — | — |
| gluster | glusterfs | >= 0 < 3.7.6-1ubuntu1+esm1 | 3.7.6-1ubuntu1+esm1 |
| gluster | glusterfs | >= 0 < 3.13.2-1ubuntu1+esm1 | 3.13.2-1ubuntu1+esm1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1LOW
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g75c-rwx3-m2xp: glusterfs server before versions 3
ghsa_unreviewed·2022-05-13·CVSS 8.1
CVE-2018-1112 [HIGH] GHSA-g75c-rwx3-m2xp: glusterfs server before versions 3
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.
OSV
CVE-2018-1112: glusterfs server before versions 3
osv·2018-04-25·CVSS 8.1
CVE-2018-1112 [HIGH] CVE-2018-1112: glusterfs server before versions 3
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.
Red Hat
glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression)
vendor_redhat·2018-04-19·CVSS 8.1
CVE-2018-1112 [HIGH] CWE-287 glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression)
glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression)
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.
It was found that fix for CVE-2018-1088 introduced a new vulnerability in the way 'auth.allow' is implemented in glusterfs server. An unauthenticated gluster client could mount gluster storage volumes.
Statement: This vulnerability affects gluster servers that use 'auth.allow' to restrict access to gluster volumes. Gluster servers using TLS to authenticate gluster clients are not affected by this. This vulnerabilit
Debian
CVE-2018-1112: glusterfs - glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.a...
vendor_debian·2018·CVSS 8.1
CVE-2018-1112 [HIGH] CVE-2018-1112: glusterfs - glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.a...
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
Exploit-DB
CloudMe 1.11.2 - Buffer Overflow ROP (DEP_ASLR)
exploitdb·2020-09-29·CVSS 9.8
CVE-2018-6892 [CRITICAL] CloudMe 1.11.2 - Buffer Overflow ROP (DEP_ASLR)
CloudMe 1.11.2 - Buffer Overflow ROP (DEP_ASLR)
---
# Exploit Title: CloudMe 1.11.2 - Buffer Overflow ROP (DEP,ASLR)
# Exploit Author: Bobby Cooke (boku)
# CVE: CVE-2018-6892
# Date: 2020-09-29
# Vendor Homepage: https://www.cloudme.com/
# Software Link: https://www.cloudme.com/downloads/CloudMe_1112.exe
# Version: 1.11.2
# Tested On: Windows 10 (x64) - 10.0.19041 Build 19041
# Script: Python 2.7
# Notes:
# This exploit uses MSVCRT.System to create a new user (boku:0v3R9000!) and add the new user to the
# Administrators group. A requirement of successful exploitation is the CloudMe.exe process must be
# running as adminstrator, such as when ran with 'Run as Administrator'; as this permission is required
# to create new users on the system. This exploit has been tested against multiple Wi
Exploit-DB
CloudMe Sync 1.11.2 Buffer Overflow - WoW64 (DEP Bypass)
exploitdb·2019-01-28·CVSS 9.8
CVE-2018-6892 [CRITICAL] CloudMe Sync 1.11.2 Buffer Overflow - WoW64 (DEP Bypass)
CloudMe Sync 1.11.2 Buffer Overflow - WoW64 (DEP Bypass)
---
# Exploit Title: CloudMe Sync v1.11.2 Buffer Overflow - WoW64 - (DEP Bypass)
# Date: 24.01.2019
# Exploit Author: Matteo Malvica
# Vendor Homepage:https://www.cloudme.com/en
# Software: https://www.cloudme.com/downloads/CloudMe_1112.exe
# Category: Remote
# Contact:https://twitter.com/matteomalvica
# Version: CloudMe Sync 1.11.2
# Tested on: Windows 7 SP1 x64
# CVE-2018-6892
# Ported to WoW64 from https://www.exploit-db.com/exploits/46218
import socket
import struct
def create_rop_chain():
# rop chain generated with mona.py - www.corelan.be
rop_gadgets = [
0x61ba8b5e, # POP EAX # RETN [Qt5Gui.dll]
0x690398a8, # ptr to &VirtualProtect() [IAT Qt5Core.dll]
0x61bdd7f5, # MOV EAX,DWORD PTR DS:[EAX] # RETN [Qt5Gui.dll]
0x68aef542,
Exploit-DB
CloudMe Sync 1.11.2 - Buffer Overflow + Egghunt
exploitdb·2019-01-22·CVSS 9.8
CVE-2018-6892 [CRITICAL] CloudMe Sync 1.11.2 - Buffer Overflow + Egghunt
CloudMe Sync 1.11.2 - Buffer Overflow + Egghunt
---
#######################################################
# Exploit Title: CloudMe Sync v1.11.2 Buffer Overflow + Egghunt
# Date: 23.04.2018
# Exploit Author:T3jv1l
# Vendor Homepage:https://www.cloudme.com/en
# Software: https://www.cloudme.com/downloads/CloudMe_1112.exe
# Category:Local
# Contact:https://twitter.com/T3jv1l
# Version: CloudMe Sync 1.11.2 - Buffer Overflow + Egghunt
# Tested on: Windows 7 SP1 x86
# CVE-2018-6892
# Real exploit https://www.exploit-db.com/exploits/44027 in version 1.11.0
# Hello subinacls and NytroRST !
#############################################################
import socket
egg = (
"\x66\x81\xca\xff\x0f\x42\x52\x6a"
"\x02\x58\xcd\x2e\x3c\x05\x5a\x74" #boom
"\xef\xb8\x62\x6f\x6f\x6d\x8b\xfa"
"\xaf\x75
Bugzilla
CVE-2018-1112 glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression) [fedora-all]
bugzilla·2018-04-24·CVSS 8.1
CVE-2018-1112 [HIGH] CVE-2018-1112 glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression) [fedora-all]
CVE-2018-1112 glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-1112 glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression)
bugzilla·2018-04-23·CVSS 8.1
CVE-2018-1112 [HIGH] CVE-2018-1112 glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression)
CVE-2018-1112 glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression)
The fix for CVE-2018-1088 in glusterfs introduced a new flaw where auth.allow allows all clients to mount volumes.
Discussion:
Upstream Fix(es):
https://review.gluster.org/#/c/19899/1..2
---
External References:
https://access.redhat.com/articles/3422521
---
Mitigation:
1. Use TLS Authentication to authenticate gluster clients to limit access to gluster storage volumes
2. The gluster server should be on LAN, firewalled to trusted systems, and not reachable from public networks.
---
Created glusterfs tracking bugs for this issue:
Affects: fedora-all [bug 1571448]
---
Statement:
This vulnerability affects gluster servers that use 'auth.allow' to restrict acc
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.htmlhttps://access.redhat.com/articles/3422521https://access.redhat.com/errata/RHSA-2018:1268https://access.redhat.com/errata/RHSA-2018:1269https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1112https://review.gluster.org/#/c/19899/1..2http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.htmlhttps://access.redhat.com/articles/3422521https://access.redhat.com/errata/RHSA-2018:1268https://access.redhat.com/errata/RHSA-2018:1269https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1112https://review.gluster.org/#/c/19899/1..2
2018-04-25
Published