Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g75c-rwx3-m2xp

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

EPSS

Процентиль: 83%
0.01953
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8
ubuntu
почти 8 лет назад

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

CVSS3: 8
redhat
почти 8 лет назад

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

CVSS3: 8
nvd
почти 8 лет назад

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

CVSS3: 8
debian
почти 8 лет назад

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when usi ...

suse-cvrf
около 6 лет назад

Security update for glusterfs

EPSS

Процентиль: 83%
0.01953
Низкий

8.8 High

CVSS3