CVE-2018-10928
Summary
| CVE | CVE-2018-10928 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-04 15:29:00 UTC |
| Updated | 2022-04-12 18:33:00 UTC |
| Description | A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1612659 – (CVE-2018-10928) CVE-2018-10928 glusterfs: Improper resolution of symlinks allows for privilege escalation |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| [security-announce] openSUSE-SU-2020:0079-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| GlusterFS: Multiple Vulnerabilities (GLSA 201904-06) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] [DLA 2806-1] glusterfs security update |
MLIST |
lists.debian.org |
|
| [SECURITY] [DLA 1510-1] glusterfs security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178862 Debian Security Update for glusterfs (DLA 2806-1)
- 710178 Gentoo Linux GlusterFS Multiple Vulnerabilities Vulnerability (GLSA 201904-06)