CVE-2018-10928
CVE-2018-10928
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 2.7%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
04 Sep 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Red Hat · glusterfsWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.htmlhttps://access.redhat.com/errata/RHSA-2018:2607https://access.redhat.com/errata/RHSA-2018:2608https://access.redhat.com/errata/RHSA-2018:3470https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10928https://lists.debian.org/debian-lts-announce/2018/09/msg00021.htmlhttps://lists.debian.org/debian-lts-announce/2021/11/msg00000.htmlhttps://security.gentoo.org/glsa/201904-06