CVE-2018-1088: High severity red hat gluster storage vulnerability
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
Other sources
A privilege escalation flaw was found in gluster snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
As reported:
When certain options are enabled in Gluster, it creates a volume called glustersharedstorage. This volume is mounted on each server in the cluster and used to share state. The volume is not intended to be mounted by storage clients as it does not contain any data that is intended to be user accessi= ble. When snapshot scheduling is enabled in Gluster, this glustersharedstorage volume is used to coordinate the snapshots. Part of that is sharing the cron job that is used to trigger scheduled snaps. The crontab file exposed in the shared volume is symlinked into each server's /etc/cron.d directory. By default, the sharedstorage volume can be mounted by any client that has access to the cluster to mount data volumes. Further, since Gluster relies = on client-reported uids, the sharedstorage volume can be written from any of these clients, permitting cron entries to be added to the system crontab directory such that they will be executed by each server as root (or any ot= her uid).
— Red Hat
Affected Software
Remediation
Information
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2018-1088?
CVE-2018-1088 is a privilege escalation flaw in the gluster snapshot scheduler.
What is the severity of CVE-2018-1088?
CVE-2018-1088 has a severity rating of 8.3 (high).
How can an attacker exploit CVE-2018-1088?
An attacker can exploit CVE-2018-1088 by mounting shared gluster storage volume and scheduling a malicious cronjob via symlink.
Which version of gluster is affected by CVE-2018-1088?
Gluster versions up to exclusive 3.8.4-54.7.el6 and up to exclusive 3.8.4-54.6.el7 are affected by CVE-2018-1088.
What is the remedy for CVE-2018-1088?
To remediate CVE-2018-1088, upgrade to gluster versions that are equal to or above 3.8.4-54.7.el6 and 3.8.4-54.6.el7.