VulnerabilityModified
CVE-2018-1088
A privilege escalation flaw was found in gluster 3.x snapshot scheduler.
HIGH 8.1EPSS 5.52%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.52% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-266
- Affected
- redhat/gluster storage · redhat/virtualization · redhat/virtualization host · redhat/enterprise linux server · opensuse/leap · debian/debian linux
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.htmlMailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1136Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1137Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1275Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1524Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1558721Issue Tracking, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00000.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201904-06Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.htmlMailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1136Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1137Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1275Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1524Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1558721Issue Tracking, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00000.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201904-06Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.