8.8
CVSSv3

CVE-2018-1112

Published: 25/04/2018 Updated: 09/10/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

glusterfs server prior to 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

Vulnerable Product Search on Vulmon Subscribe to Product

gluster glusterfs

gluster glusterfs 4.0.2

Vendor Advisories

Synopsis Important: glusterfs security update Type/Severity Security Advisory: Important Topic An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 7 for Red Hat Storage and Red Hat Gluster Storage 33 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this ...
Synopsis Important: redhat-virtualization-host security update Type/Severity Security Advisory: Important Topic An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this ...
Synopsis Important: glusterfs security update Type/Severity Security Advisory: Important Topic An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 6 for Red Hat Storage and Red Hat Gluster Storage 33 for Red Hat Enterprise Linux 6Red Hat Product Security has rated this ...
It was found that fix for CVE-2018-1088 introduced a new vulnerability in the way 'authallow' is implemented in glusterfs server An unauthenticated gluster client could mount gluster storage volumes ...