6.5
CVSSv2

CVE-2018-14651

Published: 31/10/2018 Updated: 12/02/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of these flaws to execute arbitrary code, create arbitrary files, or cause denial of service on glusterfs server nodes via symlinks to relative paths.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

redhat enterprise linux 7.0

redhat enterprise linux 6.0

gluster glusterfs

Vendor Advisories

Debian Bug report logs - #912997 glusterfs: Several security vulnerabilities Package: glusterfs; Maintainer for glusterfs is Patrick Matthäi <pmatthaei@debianorg>; Reported by: Markus Koschany <apo@debianorg> Date: Mon, 5 Nov 2018 18:12:01 UTC Severity: grave Tags: security Found in version 414-1 Fixed in vers ...
Synopsis Important: glusterfs security and bug fix update Type/Severity Security Advisory: Important Topic Updated glusterfs packages that fix multiple security issues and bugs are now available for Red Hat Gluster Storage 34 on Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as h ...
Synopsis Important: glusterfs security and bug fix update Type/Severity Security Advisory: Important Topic Updated glusterfs packages that fix multiple security issues and bugs are now available for Red Hat Gluster Storage 34 on Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as ...
It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete A remote, authenticated attacker could use one of these flaws to execute arbitrary code, create arbitrary files, or cause denial of service on glusterfs server nodes via symlinks to relative paths ...