CVE-2018-1088

A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:gluster_storage:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:virtualization_host:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

13 Feb 2023, 04:53

Type Values Removed Values Added
Summary A privilege escalation flaw was found in gluster snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink. A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
References
  • {'url': 'https://access.redhat.com/articles/3414511', 'name': 'https://access.redhat.com/articles/3414511', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2018-1088', 'name': 'https://access.redhat.com/security/cve/CVE-2018-1088', 'tags': [], 'refsource': 'MISC'}
CWE NVD-CWE-noinfo CWE-266

02 Feb 2023, 15:17

Type Values Removed Values Added
Summary A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink. A privilege escalation flaw was found in gluster snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
References
  • (MISC) https://access.redhat.com/articles/3414511 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2018-1088 -
CWE CWE-266 NVD-CWE-noinfo

30 Nov 2021, 22:00

Type Values Removed Values Added
References (MLIST) https://lists.debian.org/debian-lts-announce/2021/11/msg00000.html - (MLIST) https://lists.debian.org/debian-lts-announce/2021/11/msg00000.html - Mailing List, Third Party Advisory
References (GENTOO) https://security.gentoo.org/glsa/201904-06 - (GENTOO) https://security.gentoo.org/glsa/201904-06 - Third Party Advisory
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.html - Mailing List, Third Party Advisory
CPE cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

17 Nov 2021, 22:16

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2021/11/msg00000.html -

10 Nov 2021, 01:15

Type Values Removed Values Added
References
  • {'url': 'https://lists.debian.org/debian-lts-announce/2021/11/msg00000.html', 'name': '[debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update', 'tags': [], 'refsource': 'MLIST'}

02 Nov 2021, 03:15

Type Values Removed Values Added
CWE NVD-CWE-noinfo CWE-266
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2021/11/msg00000.html -

Information

Published : 2018-04-18 16:29

Updated : 2023-12-10 12:30


NVD link : CVE-2018-1088

Mitre link : CVE-2018-1088

CVE.ORG link : CVE-2018-1088


JSON object : View

Products Affected

redhat

  • virtualization_host
  • virtualization
  • enterprise_linux_server
  • gluster_storage

opensuse

  • leap

debian

  • debian_linux
CWE
CWE-266

Incorrect Privilege Assignment

NVD-CWE-noinfo