VDB

DEBIAN-CVE-2018-1088

DEBIAN-CVE-2018-1088 PUBLISHED CVSS 8.100000381469727 HIGH

A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.

Risk Scores

CVSS v3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:11glusterfs0, 0, 0
Debian:12glusterfs0, 0, 0
Debian:13glusterfs0, 0, 0
Debian:14glusterfs0, 0, 0

Timeline

  • Apr 18, 2018 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›