Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v93g-8xmc-xvqm

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exploit this attacker would require sufficient access to modify the extended attributes of files on a gluster volume.

It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exploit this attacker would require sufficient access to modify the extended attributes of files on a gluster volume.

EPSS

Процентиль: 79%
0.01279
Низкий

8.8 High

CVSS3

Дефекты

CWE-426

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exploit this attacker would require sufficient access to modify the extended attributes of files on a gluster volume.

CVSS3: 8.8
redhat
больше 7 лет назад

It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exploit this attacker would require sufficient access to modify the extended attributes of files on a gluster volume.

CVSS3: 8.8
nvd
больше 7 лет назад

It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exploit this attacker would require sufficient access to modify the extended attributes of files on a gluster volume.

CVSS3: 8.8
debian
больше 7 лет назад

It was found that glusterfs server does not properly sanitize file pat ...

suse-cvrf
около 6 лет назад

Security update for glusterfs

EPSS

Процентиль: 79%
0.01279
Низкий

8.8 High

CVSS3

Дефекты

CWE-426