Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1112

Опубликовано: 19 апр. 2018
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

It was found that fix for CVE-2018-1088 introduced a new vulnerability in the way 'auth.allow' is implemented in glusterfs server. An unauthenticated gluster client could mount gluster storage volumes.

Отчет

This vulnerability affects gluster servers that use 'auth.allow' to restrict access to gluster volumes. Gluster servers using TLS to authenticate gluster clients are not affected by this. This vulnerability allows any client to connect to any gluster volume which only uses auth.allow to restrict access. This issue did not affect the versions of glusterfs as shipped with Red Hat Enterprise Linux 6 and 7 because only gluster client is shipped in these products. CVE-2018-1112 affects glusterfs-server package as shipped with Red Hat Gluster Storage 3.

Меры по смягчению последствий

  1. Use TLS Authentication to authenticate gluster clients to limit access to gluster storage volumes
  2. The gluster server should be on LAN, firewalled to trusted systems, and not reachable from public networks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6glusterfsNot affected
Red Hat Enterprise Linux 7glusterfsNot affected
Red Hat Enterprise Linux 8glusterfsNot affected
Native Client for RHEL 6 for Red Hat StorageglusterfsFixedRHSA-2018:126830.04.2018
Native Client for RHEL 7 for Red Hat StorageglusterfsFixedRHSA-2018:126930.04.2018
Red Hat Gluster Storage 3.3 for RHEL 6glusterfsFixedRHSA-2018:126830.04.2018
Red Hat Gluster Storage 3.3 for RHEL 7glusterfsFixedRHSA-2018:126930.04.2018
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7glusterfsFixedRHSA-2018:126930.04.2018

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1570891glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression)

EPSS

Процентиль: 83%
0.01953
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
ubuntu
почти 8 лет назад

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

CVSS3: 8
nvd
почти 8 лет назад

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

CVSS3: 8
debian
почти 8 лет назад

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when usi ...

CVSS3: 8.8
github
больше 3 лет назад

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

suse-cvrf
около 6 лет назад

Security update for glusterfs

EPSS

Процентиль: 83%
0.01953
Низкий

8 High

CVSS3