Gluster GlusterFS 3.5

CPE Details

Gluster GlusterFS 3.5
3.5
2015-03-27
15h40 +00:00
2015-05-18
16h35 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:gluster:glusterfs:3.5:*:*:*:*:*:*:*

Informations

Vendor

gluster

Product

glusterfs

Version

3.5

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2018-10841 2018-06-20 16h00 +00:00 glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privileged gluster operations like adding other machines to trusted storage pool, start, stop, and delete volumes.
8.8
High
CVE-2018-1112 2018-04-25 10h00 +00:00 glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.
8.8
High
CVE-2017-15096 2017-10-26 17h00 +00:00 A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.
3.3
Low
CVE-2014-3619 2015-03-27 13h00 +00:00 The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.
5