CVE-2018-10841

Source
https://cve.org/CVERecord?id=CVE-2018-10841
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-10841.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-10841
Downstream
Published
2018-06-20T18:29:00.233Z
Modified
2026-03-14T14:31:35.532509Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privileged gluster operations like adding other machines to trusted storage pool, start, stop, and delete volumes.

References

Affected packages

Git / github.com/gluster/glusterfs

Affected ranges

Type
GIT
Repo
https://github.com/gluster/glusterfs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.1.8"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "9.0"
        }
    ]
}

Affected versions

v9.*
v9.0
v9.0alpha
v9.0rc0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-10841.json"