Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1112

Опубликовано: 25 апр. 2018
Источник: nvd
CVSS3: 8
CVSS3: 8.8
CVSS2: 7.5
EPSS Низкий

Описание

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gluster:glusterfs:*:*:*:*:*:*:*:*
Версия до 3.10.12 (исключая)
cpe:2.3:a:gluster:glusterfs:4.0.2:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.0243
Низкий

8 High

CVSS3

8.8 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-287
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8
ubuntu
больше 8 лет назад

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

CVSS3: 8
redhat
больше 8 лет назад

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

CVSS3: 8
debian
больше 8 лет назад

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when usi ...

CVSS3: 8.8
github
больше 4 лет назад

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

suse-cvrf
больше 6 лет назад

Security update for glusterfs

EPSS

Процентиль: 83%
0.0243
Низкий

8 High

CVSS3

8.8 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-287
NVD-CWE-noinfo