CVE-2018-10928: High severity debian linux vulnerability
A flaw was found in RPC request using gfs3symlinkreq in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.
Other sources
The Gluster filesystem allows for symlink destinations to point to filepaths outside of the mounted volume. An attacker could exploit this via a crafted request to create arbitrary files and subsequently execute arbitrary privileged commands.
— Red Hat
Affected Software
Remediation
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this flaw?
The vulnerability ID of this flaw is CVE-2018-10928.
What is the severity rating of CVE-2018-10928?
CVE-2018-10928 has a severity rating of 8.8 (high).
What is affected by CVE-2018-10928?
CVE-2018-10928 affects the glusterfs server.
How can an attacker exploit CVE-2018-10928?
An attacker can exploit CVE-2018-10928 by using a symlink destination to point to file paths outside of the gluster volume.
Are there any remedies available for CVE-2018-10928?
Yes, there are remedies available for CVE-2018-10928. Please refer to the provided references for more information.