CVE-2018-1088
Summary
| CVE | CVE-2018-1088 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-18 16:29:00 UTC |
| Updated | 2023-02-13 04:53:00 UTC |
| Description | A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1558721 – (CVE-2018-1088) CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Vendor Advisory |
| [security-announce] openSUSE-SU-2020:0079-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| CVE-2018-1088 - Red Hat Customer Portal |
MISC |
access.redhat.com |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Vendor Advisory |
| CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled - Red Hat Customer Portal |
MISC |
access.redhat.com |
|
| GlusterFS: Multiple Vulnerabilities (GLSA 201904-06) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] [DLA 2806-1] glusterfs security update |
MLIST |
lists.debian.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178862 Debian Security Update for glusterfs (DLA 2806-1)
- 710178 Gentoo Linux GlusterFS Multiple Vulnerabilities Vulnerability (GLSA 201904-06)