cbcvebase.

Gluster Glusterfs vulnerabilities

28 known vulnerabilities affecting gluster/glusterfs.

Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH15MEDIUM10LOW3

Vulnerabilities

Page 2 of 2
CVE-2018-14661P4MEDIUMCVSS 6.5v3.8.42018-10-31
CVE-2018-14661 [MEDIUM] CWE-20 CVE-2018-14661: It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vulnerable to a format string attack. A remote, authenticated attacker could use this flaw to cause remote denial of service.
nvdosv
CVE-2018-14652P4MEDIUMCVSS 6.5≥ 0, < 5.0-12018-10-31
CVE-2018-14652 [MEDIUM] CVE-2018-14652: The Gluster file system through versions 3 The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling the 'GF_XATTR_CLRLK_CMD' xattr in the 'pl_getxattr' function. A remote authenticated attacker could exploit this on a mounted volume to cause a denial of service.
osv
CVE-2018-10924P4MEDIUMCVSS 6.5≥ 3.12.11, < 3.12.14≥ 4.0.0, < 4.1.42018-09-04
CVE-2018-10924 [MEDIUM] CWE-400 CVE-2018-10924: It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.
nvdosv
CVE-2018-10914P4MEDIUMCVSS 6.5≥ 3.12.0, < 3.12.14≥ 4.1.0, < 4.1.82018-09-04
CVE-2018-10914 [MEDIUM] CWE-476 CVE-2018-10914: It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks and gluster volumes.
nvdosv
CVE-2014-3619P4MEDIUMCVSS 5.0v3.52015-03-27
CVE-2014-3619 [MEDIUM] CWE-399 CVE-2014-3619: The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.
nvdosv
CVE-2012-4417P4LOWCVSS 3.6v3.3.02012-11-18
CVE-2012-4417 [LOW] CWE-264 CVE-2012-4417: GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary fi GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
nvdosv
CVE-2012-5635P4LOWCVSS 3.6≥ 0, < 3.5.0-12013-04-09
CVE-2012-5635 [LOW] CVE-2012-5635: The GlusterFS functionality in Red Hat Storage Management Console 2 The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.
osv
CVE-2017-15096P4LOWCVSS 3.3≤ 3.9.02017-10-26
CVE-2017-15096 [LOW] CWE-476 CVE-2017-15096: A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_re A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.
nvdosv
Gluster Glusterfs vulnerabilities | cvebase