CVE-2018-1088

Description

A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
10.782

Associated Vulnerability

VulnerabilityOS Platform
(RHSA-2018:1136) Important: glusterfs security update glusterfs-3.8.4-54.6.el7.x86_64.rpmLinux
(RHSA-2018:1136) Important: glusterfs security update glusterfs-api-3.8.4-54.6.el7.x86_64.rpmLinux
(RHSA-2018:1136) Important: glusterfs security update glusterfs-api-devel-3.8.4-54.6.el7.x86_64.rpmLinux
(RHSA-2018:1136) Important: glusterfs security update glusterfs-cli-3.8.4-54.6.el7.x86_64.rpmLinux
(RHSA-2018:1136) Important: glusterfs security update glusterfs-client-xlators-3.8.4-54.6.el7.x86_64.rpmLinux
(RHSA-2018:1136) Important: glusterfs security update glusterfs-devel-3.8.4-54.6.el7.x86_64.rpmLinux
(RHSA-2018:1136) Important: glusterfs security update glusterfs-fuse-3.8.4-54.6.el7.x86_64.rpmLinux
(RHSA-2018:1136) Important: glusterfs security update glusterfs-libs-3.8.4-54.6.el7.x86_64.rpmLinux
(RHSA-2018:1136) Important: glusterfs security update glusterfs-rdma-3.8.4-54.6.el7.x86_64.rpmLinux
(RHSA-2018:1136) Important: glusterfs security update python-gluster-3.8.4-54.6.el7.noarch.rpmLinux
(RHSA-2018:1137) Important: glusterfs security update glusterfs-3.8.4-54.7.el6.x86_64.rpmLinux
(RHSA-2018:1137) Important: glusterfs security update glusterfs-api-3.8.4-54.7.el6.x86_64.rpmLinux
(RHSA-2018:1137) Important: glusterfs security update glusterfs-api-devel-3.8.4-54.7.el6.x86_64.rpmLinux
(RHSA-2018:1137) Important: glusterfs security update glusterfs-cli-3.8.4-54.7.el6.x86_64.rpmLinux
(RHSA-2018:1137) Important: glusterfs security update glusterfs-client-xlators-3.8.4-54.7.el6.x86_64.rpmLinux
(RHSA-2018:1137) Important: glusterfs security update glusterfs-devel-3.8.4-54.7.el6.x86_64.rpmLinux
(RHSA-2018:1137) Important: glusterfs security update glusterfs-fuse-3.8.4-54.7.el6.x86_64.rpmLinux
(RHSA-2018:1137) Important: glusterfs security update glusterfs-libs-3.8.4-54.7.el6.x86_64.rpmLinux
(RHSA-2018:1137) Important: glusterfs security update glusterfs-rdma-3.8.4-54.7.el6.x86_64.rpmLinux
(RHSA-2018:1137) Important: glusterfs security update python-gluster-3.8.4-54.7.el6.noarch.rpmLinux
(RHSA-2018:1268) Important: glusterfs security update glusterfs-3.8.4-54.9.el6.x86_64.rpmLinux
(RHSA-2018:1268) Important: glusterfs security update glusterfs-api-3.8.4-54.9.el6.x86_64.rpmLinux
(RHSA-2018:1268) Important: glusterfs security update glusterfs-api-devel-3.8.4-54.9.el6.x86_64.rpmLinux
(RHSA-2018:1268) Important: glusterfs security update glusterfs-cli-3.8.4-54.9.el6.x86_64.rpmLinux
(RHSA-2018:1268) Important: glusterfs security update glusterfs-client-xlators-3.8.4-54.9.el6.x86_64.rpmLinux
(RHSA-2018:1268) Important: glusterfs security update glusterfs-devel-3.8.4-54.9.el6.x86_64.rpmLinux
(RHSA-2018:1268) Important: glusterfs security update glusterfs-fuse-3.8.4-54.9.el6.x86_64.rpmLinux
(RHSA-2018:1268) Important: glusterfs security update glusterfs-libs-3.8.4-54.9.el6.x86_64.rpmLinux
(RHSA-2018:1268) Important: glusterfs security update glusterfs-rdma-3.8.4-54.9.el6.x86_64.rpmLinux
(RHSA-2018:1268) Important: glusterfs security update python-gluster-3.8.4-54.9.el6.noarch.rpmLinux
(RHSA-2018:1269) Important: glusterfs security update glusterfs-3.8.4-54.8.el7.x86_64.rpmLinux
(RHSA-2018:1269) Important: glusterfs security update glusterfs-api-3.8.4-54.8.el7.x86_64.rpmLinux
(RHSA-2018:1269) Important: glusterfs security update glusterfs-api-devel-3.8.4-54.8.el7.x86_64.rpmLinux
(RHSA-2018:1269) Important: glusterfs security update glusterfs-cli-3.8.4-54.8.el7.x86_64.rpmLinux
(RHSA-2018:1269) Important: glusterfs security update glusterfs-client-xlators-3.8.4-54.8.el7.x86_64.rpmLinux
(RHSA-2018:1269) Important: glusterfs security update glusterfs-devel-3.8.4-54.8.el7.x86_64.rpmLinux
(RHSA-2018:1269) Important: glusterfs security update glusterfs-fuse-3.8.4-54.8.el7.x86_64.rpmLinux
(RHSA-2018:1269) Important: glusterfs security update glusterfs-libs-3.8.4-54.8.el7.x86_64.rpmLinux
(RHSA-2018:1269) Important: glusterfs security update glusterfs-rdma-3.8.4-54.8.el7.x86_64.rpmLinux
(RHSA-2018:1269) Important: glusterfs security update python-gluster-3.8.4-54.8.el7.noarch.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234