Back to Database
Status published
High
CVE-2018-1112
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using...
Vulnerability Description
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-1112
Credits & Attribution
No credits recorded in the NVD database.
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1112
- https://review.gluster.org/#/c/19899/1..2
- https://access.redhat.com/articles/3422521
- https://access.redhat.com/errata/RHSA-2018:1268
- https://access.redhat.com/errata/RHSA-2018:1269
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.html
More from unspecified
View All →CVE-2022-4642
tatoeba2 Profile Name cross site scripting
Low
3.5
CVE-2022-4641
pig-vector LogisticRegression.java LogisticRegression temp file
Low
2.5
CVE-2022-4639
sslh Packet Dumping probe.c hexdump format string
Medium
5.6
CVE-2022-4638
collective.contact.widget widgets.py title cross site scripting
Low
3.5
CVE-2022-4631
WP-Ban ban-options.php cross site scripting
Low
3.5
Affected Vendor
unspecified
View all reports →Affected Software
glusterfs
Vulnerable Versions:
glusterfs 3.10.12, glusterfs 4.0.2
Timeline
Official Publish:
April 25th, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H