CVE-2018-1088: High severity red hat gluster storage vulnerability

Published Mar 20, 2018
·
Updated

A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.

Other sources

A privilege escalation flaw was found in gluster snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.

As reported:

When certain options are enabled in Gluster, it creates a volume called glustersharedstorage. This volume is mounted on each server in the cluster and used to share state. The volume is not intended to be mounted by storage clients as it does not contain any data that is intended to be user accessi= ble. When snapshot scheduling is enabled in Gluster, this glustersharedstorage volume is used to coordinate the snapshots. Part of that is sharing the cron job that is used to trigger scheduled snaps. The crontab file exposed in the shared volume is symlinked into each server's /etc/cron.d directory. By default, the sharedstorage volume can be mounted by any client that has access to the cluster to mount data volumes. Further, since Gluster relies = on client-reported uids, the sharedstorage volume can be written from any of these clients, permitting cron entries to be added to the system crontab directory such that they will be executed by each server as root (or any ot= her uid).

Red Hat

Affected Software

13 affected componentsFixes available
redhat/glusterfs<0:3.8.4-54.7.el6
0:3.8.4-54.7.el6
redhat/glusterfs<0:3.8.4-54.6.el7
0:3.8.4-54.6.el7
redhat/redhat-release-virtualization-host<0:4.1-11.0.el7
0:4.1-11.0.el7
redhat/imgbased<0:1.0.16-0.1.el7e
0:1.0.16-0.1.el7e
redhat/ovirt-node-ng<0:4.2.0-0.20170814.0.el7
0:4.2.0-0.20170814.0.el7
redhat/redhat-release-virtualization-host<0:4.2-3.0.el7
0:4.2-3.0.el7
redhat Gluster Storage>=3.0<=3.13.2
redhat Virtualization=4.0
redhat Virtualization Host=4.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server=7.0
openSUSE Leap=15.1
Debian Debian Linux=9.0

Remediation

Information

To limit exposure of gluster server nodes : 1. gluster server should be on LAN and not reachable from public networks. 2. Use gluster auth.allow and auth.reject. 3. Use TLS certificates between gluster server nodes and clients. Caveat: This would only mitigate attacks from unauthorized malicious clients. gluster clients allowed by auth.allow or having signed TLS client certificates would still be able to trigger this attack.

Event History

Mar 20, 2018
Data Sourced
via Red Hat·09:30 PM
DescriptionSeverityAffected Software
Apr 18, 2018
CVE Published
12:00 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2018-1088?

CVE-2018-1088 is a privilege escalation flaw in the gluster snapshot scheduler.

2

What is the severity of CVE-2018-1088?

CVE-2018-1088 has a severity rating of 8.3 (high).

3

How can an attacker exploit CVE-2018-1088?

An attacker can exploit CVE-2018-1088 by mounting shared gluster storage volume and scheduling a malicious cronjob via symlink.

4

Which version of gluster is affected by CVE-2018-1088?

Gluster versions up to exclusive 3.8.4-54.7.el6 and up to exclusive 3.8.4-54.6.el7 are affected by CVE-2018-1088.

5

What is the remedy for CVE-2018-1088?

To remediate CVE-2018-1088, upgrade to gluster versions that are equal to or above 3.8.4-54.7.el6 and 3.8.4-54.6.el7.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203