Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-884c-j6hw-f37p

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.

A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.

EPSS

Процентиль: 85%
0.02699
Низкий

8.8 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 8 лет назад

A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.

CVSS3: 8.8
redhat
почти 8 лет назад

A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.

CVSS3: 8.8
nvd
почти 8 лет назад

A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.

CVSS3: 8.8
debian
почти 8 лет назад

A flaw was found in RPC request using gfs3_symlink_req in glusterfs se ...

suse-cvrf
больше 6 лет назад

Security update for glusterfs

EPSS

Процентиль: 85%
0.02699
Низкий

8.8 High

CVSS3

Дефекты

CWE-59