CVE-2018-10928 PUBLISHED

A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.

EPSS 1.65% · 81.9th percentile

Risk Scores

EPSS Score
1.65%
81.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSglusterfs0, 3.2.7-3ubuntu2, 3.4.1-1ubuntu1
Ubuntu:Pro:18.04:LTSglusterfs3.13.2-1ubuntu1, 3.12.3-1, 3.13.0-1
Ubuntu:Pro:16.04:LTSglusterfs3.7.3-1ubuntu1, 3.7.3-1ubuntu2, 3.7.6-1ubuntu1

Timeline

References

Open in Interactive Console →