PT-2018-10172 · Red Hat+4 · Glusterfs+4

Michael Hanselmann

+1

·

Published

2018-09-04

·

Updated

2022-04-22

·

CVE-2018-10904

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions glusterfs (affected versions not specified)
Description A flaw was discovered in the glusterfs server where it fails to properly sanitize file paths in the trusted.io-stats-dump extended attribute used by the debug/io-stats translator. This allows an attacker to create files and execute arbitrary code if they have sufficient access to modify the extended attributes of files on a gluster volume.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2484
CESA-2018_2607
CVE-2018-10904
DLA-1510-1
DLA-2806-1
OPENSUSE-SU-2020:0079-1
OPENSUSE-SU-2020_0079-1
OPENSUSE-SU-2024:10794-1
RHSA-2018:2607
RHSA-2018:2608
RHSA-2018:3470
USN-4770-1

Affected Products

Alt Linux
Centos
Suse
Ubuntu
Glusterfs