Vulnerability Description
glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privileged gluster operations like adding other machines to trusted storage pool, start, stop, and delete volumes.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gluster | Glusterfs | < 4.1.8 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2018:1954Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1955Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10841Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00000.htmlMailing ListThird Party Advisory
- https://review.gluster.org/#/c/20328/PatchThird Party Advisory
- https://security.gentoo.org/glsa/201904-06Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1954Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1955Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10841Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00000.htmlMailing ListThird Party Advisory
- https://review.gluster.org/#/c/20328/PatchThird Party Advisory
- https://security.gentoo.org/glsa/201904-06Third Party Advisory
FAQ
What is CVE-2018-10841?
CVE-2018-10841 is a vulnerability with a CVSS score of 8.8 (HIGH). glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool...
How severe is CVE-2018-10841?
CVE-2018-10841 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10841?
Check the references section above for vendor advisories and patch information. Affected products include: Gluster Glusterfs, Debian Debian Linux.