Vulnerabilities
Vulnerable Software
Gluster:  >> Glusterfs  >> 3.1.3  Security Vulnerabilities
glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privileged gluster operations like adding other machines to trusted storage pool, start, stop, and delete volumes.
CVSS Score
6.6
EPSS Score
0.004
Published
2018-06-20
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.
CVSS Score
8.0
EPSS Score
0.033
Published
2018-04-25
A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.
CVSS Score
3.3
EPSS Score
0.001
Published
2017-10-26


Contact Us

Shodan ® - All rights reserved