CVE-2018-1088 PUBLISHED

A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.

EPSS 10.78% · 93.3th percentile

Risk Scores

EPSS Score
10.78%
93.3th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSglusterfs3.13.2-1ubuntu1, 3.12.3-1, 3.13.0-1
Ubuntu:Pro:16.04:LTSglusterfs3.7.3-1ubuntu1, 3.7.3-1ubuntu2, 3.7.6-1ubuntu1

Timeline

References

Open in Interactive Console →