cbcvebase.

Redhat Gluster Storage vulnerabilities

25 known vulnerabilities affecting redhat/gluster_storage.

Total CVEs
25
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL1HIGH14MEDIUM10

Vulnerabilities

Page 2 of 2
CVE-2019-3880P4MEDIUMCVSS 5.4v3.02019-04-09
CVE-2019-3880 [MEDIUM] CWE-22 CVE-2019-3880: A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share. Versions before 4.8.11, 4.9.6 and 4.10.2 are vulnerable.
nvd
CVE-2018-14652P4MEDIUMCVSS 6.5≥ 3.0.0, ≤ 3.1.2≥ 4.1.0, ≤ 4.1.82018-10-31
CVE-2018-14652 [MEDIUM] CWE-120 CVE-2018-14652: The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'f The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling the 'GF_XATTR_CLRLK_CMD' xattr in the 'pl_getxattr' function. A remote authenticated attacker could exploit this on a mounted volume to cause a denial of service.
nvd
CVE-2017-15085P4MEDIUMCVSS 5.9v3.32017-11-08
CVE-2017-15085 [MEDIUM] CVE-2017-15085: It was discovered that the fix for CVE-2017-12150 was not properly shipped in erratum RHSA-2017:2858 It was discovered that the fix for CVE-2017-12150 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
nvd
CVE-2018-1000808P4MEDIUMCVSS 5.9v3.02018-10-08
CVE-2018-1000808 [MEDIUM] CWE-404 CVE-2018-1000808: Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Rel Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Reference vulnerability in PKCS #12 Store that can result in Denial of service if memory runs low or is exhausted. This attack appear to be exploitable via Depends upon calling application, however it could be as s
nvd
CVE-2020-10763P4MEDIUMCVSS 5.5v3.0v3.52020-11-24
CVE-2020-10763 [MEDIUM] CWE-532 CVE-2020-10763: An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.
nvd
Redhat Gluster Storage vulnerabilities | cvebase