Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10913

Опубликовано: 04 сент. 2018
Источник: redhat
CVSS3: 3.5
EPSS Низкий

Описание

An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.

Отчет

This issue did not affect Red Hat Enterprise Linux 6 and 7 as the flaw is present in glusterfs-server, which is not shipped there. This flaw affects glusterfs versions included in Red Hat Virtualization 4 Hypervisor. However, in recommended configurations, the vulnerability is only exposed to hypervisor administrators and can not be exploited from virtual machines or other hosts on the network.

Меры по смягчению последствий

SELinux mitigates this issue on Red Hat Gluster Storage 3. SELinux should be in enforcing mode only as permissive mode does not block attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6glusterfsNot affected
Red Hat Enterprise Linux 7glusterfsNot affected
Red Hat Enterprise Linux 8glusterfsNot affected
Native Client for RHEL 6 for Red Hat StorageglusterfsFixedRHSA-2018:260804.09.2018
Native Client for RHEL 7 for Red Hat StorageglusterfsFixedRHSA-2018:260704.09.2018
Red Hat Gluster Storage 3.4 for RHEL 6glusterfsFixedRHSA-2018:260804.09.2018
Red Hat Gluster Storage 3.4 for RHEL 6redhat-release-serverFixedRHSA-2018:260804.09.2018
Red Hat Gluster Storage 3.4 for RHEL 6redhat-storage-serverFixedRHSA-2018:260804.09.2018
Red Hat Gluster Storage 3.4 for RHEL 7glusterfsFixedRHSA-2018:260704.09.2018
Red Hat Gluster Storage 3.4 for RHEL 7redhat-release-serverFixedRHSA-2018:260704.09.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-209
https://bugzilla.redhat.com/show_bug.cgi?id=1607618glusterfs: Information Exposure in posix_get_file_contents function in posix-helpers.c

EPSS

Процентиль: 77%
0.01007
Низкий

3.5 Low

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.

CVSS3: 6.5
nvd
больше 7 лет назад

An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.

CVSS3: 6.5
debian
больше 7 лет назад

An information disclosure vulnerability was discovered in glusterfs se ...

CVSS3: 6.5
github
почти 4 года назад

An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.

suse-cvrf
около 6 лет назад

Security update for glusterfs

EPSS

Процентиль: 77%
0.01007
Низкий

3.5 Low

CVSS3