CVE-2018-1112 REJECTED

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

EPSS 1.95% · 83.4th percentile

Risk Scores

EPSS Score
1.95%
83.4th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSglusterfs0, 3.7.3-1ubuntu1, 3.7.3-1ubuntu2
Ubuntu:Pro:18.04:LTSglusterfs0, 3.11.2-1, 3.12.1-1

Timeline

References

Open in Interactive Console →