glusterfs is vulnerable to privilege escalation on gluster server nodes....
Vulnerability Description
glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privileged gluster operations like adding other machines to trusted storage pool, start, stop, and delete volumes.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-10841
Credits & Attribution
No credits recorded in the NVD database.
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10841
- https://access.redhat.com/errata/RHSA-2018:1955
- https://review.gluster.org/#/c/20328/
- https://access.redhat.com/errata/RHSA-2018:1954
- https://security.gentoo.org/glsa/201904-06
- https://lists.debian.org/debian-lts-announce/2021/11/msg00000.html
More from Red Hat
View All →Affected Vendor
Red Hat
View all reports →