Incorrect Privilege Assignment Affecting glusterfs-rdma package, versions <0:3.8.4-54.6.el7rhgs


Severity

Recommended
0.0
high
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
5.55% (92nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL7-GLUSTERFSRDMA-4438330
  • published1 Nov 2021
  • disclosed18 Apr 2018

Introduced: 18 Apr 2018

CVE-2018-1088  (opens in a new tab)
CWE-266  (opens in a new tab)

How to fix?

Upgrade RHEL:7 glusterfs-rdma to version 0:3.8.4-54.6.el7rhgs or higher.
This issue was patched in RHSA-2018:1136.

NVD Description

Note: Versions mentioned in the description apply only to the upstream glusterfs-rdma package and not the glusterfs-rdma package as distributed by RHEL. See How to fix? for RHEL:7 relevant fixed versions and status.

A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.

CVSS Base Scores

version 3.1