Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1112

Опубликовано: 25 апр. 2018
Источник: nvd
CVSS3: 8
CVSS3: 8.8
CVSS2: 7.5
EPSS Низкий

Описание

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gluster:glusterfs:*:*:*:*:*:*:*:*
Версия до 3.10.12 (исключая)
cpe:2.3:a:gluster:glusterfs:4.0.2:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.01953
Низкий

8 High

CVSS3

8.8 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-287
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8
ubuntu
почти 8 лет назад

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

CVSS3: 8
redhat
почти 8 лет назад

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

CVSS3: 8
debian
почти 8 лет назад

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when usi ...

CVSS3: 8.8
github
больше 3 лет назад

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

suse-cvrf
около 6 лет назад

Security update for glusterfs

EPSS

Процентиль: 83%
0.01953
Низкий

8 High

CVSS3

8.8 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-287
NVD-CWE-noinfo