Redhat Fuse vulnerabilities
38 known vulnerabilities affecting redhat/fuse.
Total CVEs
38
CISA KEV
3
actively exploited
Public exploits
8
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH12MEDIUM10LOW8
Vulnerabilities
Page 2 of 2
CVE-2018-10906HIGHCVSS 7.8PoC≥ 0, < 2.9.8-12018-07-24
CVE-2018-10906 [HIGH] CVE-2018-10906: In fuse before versions 2
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, po
osv
CVE-2018-1258HIGHCVSS 8.8v7.3.02018-05-11
CVE-2018-1258 [HIGH] CWE-863 CVE-2018-1258: Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contain
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
nvd
CVE-2018-1270CRITICALCVSS 9.8v1.0.02018-04-06
CVE-2018-1270 [CRITICAL] CWE-94 CVE-2018-1270: Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution
nvd
CVE-2018-1199MEDIUMCVSS 5.3v1.02018-03-16
CVE-2018-1199 [MEDIUM] CWE-20 CVE-2018-1199: Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and
Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint. The
nvd
CVE-2017-12617HIGHCVSS 8.1KEVPoCv1.02017-10-04
CVE-2017-12617 [HIGH] CWE-434 CVE-2017-12617: When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code
nvd
CVE-2017-7957HIGHCVSS 7.5v1.02017-04-29
CVE-2017-7957 [HIGH] CWE-20 CVE-2017-7957: XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to creat
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("") call.
nvd
CVE-2017-5645CRITICALCVSS 9.8PoCv1.02017-04-17
CVE-2017-5645 [CRITICAL] CWE-502 CVE-2017-5645: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive s
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
nvd
CVE-2016-4437CRITICALCVSS 9.8KEVPoCv1.02016-06-07
CVE-2016-4437 [CRITICAL] CWE-321 CVE-2016-4437: Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature,
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
nvd
CVE-2016-1233HIGHCVSS 7.8≥ 0, < 2.9.5-12016-01-26
CVE-2016-1233 [HIGH] CVE-2016-1233: An unspecified udev rule in the Debian fuse package in jessie before 2
An unspecified udev rule in the Debian fuse package in jessie before 2.9.3-15+deb8u2, in stretch before 2.9.5-1, and in sid before 2.9.5-1 sets world-writable permissions for the /dev/cuse character device, which allows local users to gain privileges via a character device in /dev, related to an ioctl.
osv
CVE-2015-3202LOWCVSS 3.6PoC≥ 0, < 2.9.3-162015-07-02
CVE-2015-3202 [LOW] CVE-2015-3202: fusermount in FUSE before 2
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
osv
CVE-2015-1427CRITICALCVSS 9.8KEVPoCv1.0.02015-02-17
CVE-2015-1427 [CRITICAL] CVE-2015-1427: The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attac
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
nvd
CVE-2011-0541LOWCVSS 3.3≥ 0, < 2.8.5-12011-09-02
CVE-2011-0541 [LOW] CVE-2011-0541: fuse 2
fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.
osv
CVE-2011-0542LOWCVSS 3.3≥ 0, < 2.8.5-12011-09-02
CVE-2011-0542 [LOW] CVE-2011-0542: fusermount in fuse 2
fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified vectors.
osv
CVE-2011-0543LOWCVSS 3.3≥ 0, < 2.8.5-12011-09-02
CVE-2011-0543 [LOW] CVE-2011-0543: Certain legacy functionality in fusermount in fuse 2
Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.
osv
CVE-2010-3879LOWCVSS 3.3PoC≥ 0, < 2.8.5-12011-01-22
CVE-2010-3879 [LOW] CVE-2010-3879: FUSE, possibly 2
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.
osv
CVE-2010-0789LOWCVSS 3.3≥ 0, < 2.8.1-1.22010-03-02
CVE-2010-0789 [LOW] CVE-2010-0789: fusermount in FUSE before 2
fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint.
osv
CVE-2005-3531LOWCVSS 2.1≥ 0, < 2.4.1-0.12005-11-23
CVE-2005-3531 [LOW] CVE-2005-3531: fusermount in FUSE before 2
fusermount in FUSE before 2.4.1, if installed setuid root, allows local users to corrupt /etc/mtab and possibly modify mount options by performing a mount over a directory whose name contains certain special characters.
osv
CVE-2005-1858LOWCVSS 2.1PoC≥ 0, < 2.3.0-12005-06-03
CVE-2005-1858 [LOW] CVE-2005-1858: FUSE 2
FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local users to obtain sensitive information.
osv
← Previous2 / 2