Candidate: CVE-2018-10841 PublicDate: 2018-06-20 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10841 https://review.gluster.org/#/c/20328/ http://git.gluster.org/cgit/glusterfs.git/commit/?id=e8d928e34680079e42be6947ffacc4ddd7defca2 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10841 Description: glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privileged gluster operations like adding other machines to trusted storage pool, start, stop, and delete volumes. Ubuntu-Description: It was discovered that GlusterFS incorrectly handled user permissions. An authenticated attacker could possibly use this to add himself to trusted storage pool and performing privileged operations on volumes. Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=901968 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [8.8 HIGH] nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_glusterfs: upstream_glusterfs: needs-triage precise/esm_glusterfs: DNE trusty_glusterfs: not-affected (code not present) trusty/esm_glusterfs: not-affected (code not present) xenial_glusterfs: ignored (end of standard support, was needed) artful_glusterfs: ignored (reached end-of-life) bionic_glusterfs: needed cosmic_glusterfs: released (4.1.2-1) disco_glusterfs: not-affected (4.1.2-1) eoan_glusterfs: not-affected (4.1.2-1) focal_glusterfs: not-affected (4.1.2-1) groovy_glusterfs: not-affected (4.1.2-1) hirsute_glusterfs: not-affected (4.1.2-1) impish_glusterfs: not-affected (4.1.2-1) jammy_glusterfs: not-affected (4.1.2-1) devel_glusterfs: not-affected (4.1.2-1)