Gluster
Glusterfs: vulnerabilidades y CVE
Glusterfs tiene 23 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-26253 | Alta (7.5) | 0.91% | — | 21 feb 2023 | In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse-bridge.c notify stack-based buffer over-read. |
| CVE-2022-48340 | Alta (7.5) | 0.87% | — | 21 feb 2023 | In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free. |
| CVE-2018-14660 | Media (6.5) | 2.5% | — | 1 nov 2018 | A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single… |
| CVE-2018-14651 | Alta (8.8) | 3.2% | — | 31 oct 2018 | It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of these flaws to execute arbitrary code,… |
| CVE-2018-14661 | Media (6.5) | 2.7% | — | 31 oct 2018 | It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vulnerable to a format string attack. A remote, authenticated attacker… |
| CVE-2018-10930 | Media (6.5) | 2.1% | — | 4 sept 2018 | A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume. |
| CVE-2018-10929 | Alta (8.8) | 3.3% | — | 4 sept 2018 | A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw to create arbitrary files and execute arbitrary code on glusterfs server nodes. |
| CVE-2018-10928 | Alta (8.8) | 2.7% | — | 4 sept 2018 | A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create… |
| CVE-2018-10927 | Alta (8.1) | 2.8% | — | 4 sept 2018 | A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by crashing gluster brick process. |
| CVE-2018-10926 | Alta (8.8) | 2.6% | — | 4 sept 2018 | A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execute arbitrary code on… |
| CVE-2018-10924 | Media (6.5) | 1.9% | — | 4 sept 2018 | It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host… |
| CVE-2018-10923 | Alta (8.1) | 1.7% | — | 4 sept 2018 | It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any… |
| CVE-2018-10914 | Media (6.5) | 2.4% | — | 4 sept 2018 | It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result… |
| CVE-2018-10913 | Media (6.5) | 2.1% | — | 4 sept 2018 | An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file. |
| CVE-2018-10911 | Alta (7.5) | 3.1% | — | 4 sept 2018 | A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value. |
| CVE-2018-10907 | Alta (8.8) | 3.4% | — | 4 sept 2018 | It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit… |
| CVE-2018-10904 | Alta (8.8) | 3.0% | — | 4 sept 2018 | It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and… |
| CVE-2018-10841 | Alta (8.8) | 1.3% | — | 20 jun 2018 | glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform… |
| CVE-2018-1112 | Alta (8.8) | 2.4% | — | 25 abr 2018 | glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this… |
| CVE-2017-15096 | Baja (3.3) | 0.32% | — | 26 oct 2017 | A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service. |
| CVE-2014-3619 | Media (5) | 2.7% | — | 27 mar 2015 | The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header. |
| CVE-2012-5635 | Baja (2.1) | 0.32% | — | 9 abr 2013 | The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1)… |
| CVE-2012-4417 | Baja (3.6) | 0.34% | — | 18 nov 2012 | GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names. |