6.8
CVSSv2

CVE-2018-1088

Published: 18/04/2018 Updated: 13/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 607
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux server 7.0

redhat enterprise linux server 6.0

redhat virtualization host 4.0

redhat virtualization 4.0

redhat gluster storage

opensuse leap 15.1

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #896128 glusterfs: CVE-2018-1088 privilege escalation flaw Package: glusterfs; Maintainer for glusterfs is Patrick Matthäi <pmatthaei@debianorg>; Reported by: Markus Koschany <apo@debianorg> Date: Thu, 19 Apr 2018 21:09:01 UTC Severity: grave Tags: security, upstream Found in version 40 ...
Synopsis Important: glusterfs security update Type/Severity Security Advisory: Important Topic An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 6 for Red Hat Storage and Red Hat Gluster Storage 33 for Red Hat Enterprise Linux 6Red Hat Product Security has rated this ...
Synopsis Important: glusterfs security update Type/Severity Security Advisory: Important Topic An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 7 for Red Hat Storage and Red Hat Gluster Storage 33 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this ...
Synopsis Important: glusterfs security update Type/Severity Security Advisory: Important Topic An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 7 for Red Hat Storage and Red Hat Gluster Storage 33 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this ...
Synopsis Important: redhat-virtualization-host security update Type/Severity Security Advisory: Important Topic An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this ...
Synopsis Important: glusterfs security update Type/Severity Security Advisory: Important Topic An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 6 for Red Hat Storage and Red Hat Gluster Storage 33 for Red Hat Enterprise Linux 6Red Hat Product Security has rated this ...
Synopsis Important: redhat-virtualization-host bug fix and enhancement update Type/Severity Security Advisory: Important Topic Updated redhat-virtualization-host packages that fix several bugs and add various enhancements are now available Description The redhat-virtualization-host package ...
A privilege escalation flaw was found in gluster snapshot scheduler Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink ...