CVE-2018-1088 Affecting glusterfs package, versions <4.0.2-1


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
1.19% (85th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN10-GLUSTERFS-294650
  • published18 Apr 2018
  • disclosed18 Apr 2018

Introduced: 18 Apr 2018

CVE-2018-1088  (opens in a new tab)

How to fix?

Upgrade Debian:10 glusterfs to version 4.0.2-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream glusterfs package and not the glusterfs package as distributed by Debian. See How to fix? for Debian:10 relevant fixed versions and status.

A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.

CVSS Scores

version 3.1