ZeroHour

CVE-2018-10841

CVSS 3.1
8.8 high
EPSS
1%p68
Published
()
Modified
Description

glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privileged gluster operations like adding other machines to trusted storage pool, start, stop, and delete volumes.

Vendors
glusterdebian
Products
glusterfs, debian linux
Weakness
CWE-288
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.