ZeroHour

CVE-2018-1088

CVSS 3.1
8.1 high
EPSS
6%p92
Published
()
Modified
Description

A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.

Vendors
redhatopensusedebian
Products
gluster storage, virtualization, virtualization host, enterprise linux server, leap, debian linux
Weakness
CWE-266
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.