CVE-2018-14651 PUBLISHED

It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of these flaws to execute arbitrary code, create arbitrary files, or cause denial of service on glusterfs server nodes via symlinks to relative paths.

EPSS 2.19% · 84.3th percentile

Risk Scores

EPSS Score
2.19%
84.3th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSglusterfs3.13.2-1ubuntu1, 0, 3.11.2-1
Ubuntu:Pro:14.04:LTSglusterfs3.2.7-3ubuntu2, 3.4.1-1ubuntu1, 3.4.1-2ubuntu1
Ubuntu:Pro:16.04:LTSglusterfs3.7.3-1ubuntu1, 3.7.3-1ubuntu2, 3.7.6-1ubuntu1

Timeline

References

Open in Interactive Console →