Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-10841

Опубликовано: 20 июн. 2018
Источник: nvd
CVSS3: 6.6
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privileged gluster operations like adding other machines to trusted storage pool, start, stop, and delete volumes.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gluster:glusterfs:*:*:*:*:*:*:*:*
Версия до 4.1.8 (исключая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 52%
0.00296
Низкий

6.6 Medium

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-288
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privileged gluster operations like adding other machines to trusted storage pool, start, stop, and delete volumes.

CVSS3: 6.6
redhat
больше 7 лет назад

glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privileged gluster operations like adding other machines to trusted storage pool, start, stop, and delete volumes.

CVSS3: 8.8
debian
больше 7 лет назад

glusterfs is vulnerable to privilege escalation on gluster server node ...

CVSS3: 8.8
github
больше 3 лет назад

glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privileged gluster operations like adding other machines to trusted storage pool, start, stop, and delete volumes.

EPSS

Процентиль: 52%
0.00296
Низкий

6.6 Medium

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-288
NVD-CWE-noinfo