Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mohit Agrawal

Researcher fromRed Hat
#29618of 53,633
8.8Total CVSS
Vulnerabilities · 1
PT-2018-10135
8.8
2018-06-20
Red Hat · Glusterfs · CVE-2018-10841
**Name of the Vulnerable Software and Affected Versions** glusterfs (affected versions not specified) **Description** The issue allows for privilege escalation on gluster server nodes. An authenticated gluster client using TLS can exploit this by utilizing the gluster cli with the `--remote-host` command. This enables the client to add itself to the trusted storage pool and perform privileged gluster operations, including adding other machines to the trusted storage pool, as well as starting, stopping, and deleting volumes. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.