cbcvebase.
CVE-2018-14654
published 2018-10-31

CVE-2018-14654: The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volumes could…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volumes could exploit this via the 'GF_XATTROP_ENTRY_IN_KEY' xattrop to create arbitrary, empty files on the target server.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianglusterfs< glusterfs 5.1-1 (bookworm)glusterfs 5.1-1 (bookworm)
glusterglusterfs>= 0 < 5.1-15.1-1
glusterglusterfs>= 0 < 5.1-15.1-1
glusterglusterfs>= 0 < 5.1-15.1-1
glusterglusterfs>= 0 < 5.1-15.1-1
glusterglusterfs>= 0 < 3.4.2-1ubuntu1+esm13.4.2-1ubuntu1+esm1
glusterglusterfs>= 0 < 3.7.6-1ubuntu1+esm13.7.6-1ubuntu1+esm1
glusterglusterfs>= 0 < 3.13.2-1ubuntu1+esm13.13.2-1ubuntu1+esm1
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_virtualization
redhatgluster_storage<= 4.1.4
redhatvirtualization
redhatvirtualization_host
the_gluster_projectglusterfs

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
osv6.5MEDIUM