CVE-2018-10930: Input Validation
A flaw was found in RPC request using gfs3renamereq in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume.
Other sources
The Gluster filesystem during a file rename only validates that the source path exists within the mounted volume. This can allow an attacker to rename files in locations outside a mounted volume.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2018-10930.
What is the severity of CVE-2018-10930?
The severity of CVE-2018-10930 is high.
What is the affected software for CVE-2018-10930?
The affected software for CVE-2018-10930 is GlusterFS.
How can an attacker exploit CVE-2018-10930?
An attacker can exploit CVE-2018-10930 by using a flaw in RPC request in the GlusterFS server to write to a destination outside the Gluster volume.
Where can I find more information about CVE-2018-10930?
You can find more information about CVE-2018-10930 at the following references: [link1](https://access.redhat.com/security/updates/classification/), [link2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1625085), [link3](https://access.redhat.com/errata/RHSA-2018:2607).