[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256288

 
 

909

 
 

199146

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-1088 -- glusterfs-common

ID: oval:org.secpod.oval:def:1901622Date: (C)2019-04-22   (M)2023-12-20
Class: VULNERABILITYFamily: unix




A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.

Platform:
Ubuntu 16.04
Ubuntu 18.04
Product:
glusterfs-common
Reference:
CVE-2018-1088
CVE    1
CVE-2018-1088
CPE    3
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/o:ubuntu:ubuntu_linux:18.04
cpe:/a:gluster:glusterfs-common

© SecPod Technologies