SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-1088

A privilege escalation flaw was found in gluster 3.x snapshot scheduler.

HIGH 8.1EPSS 5.52%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (5.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
5.52% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-266
Affected
redhat/gluster storage · redhat/virtualization · redhat/virtualization host · redhat/enterprise linux server · opensuse/leap · debian/debian linux
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.