CVE-2018-1112: High severity centos glusterfs vulnerability
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.
Other sources
The fix for CVE-2018-1088 in glusterfs introduced a new flaw where auth.allow allows all clients to mount volumes.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this glusterfs server vulnerability?
The vulnerability ID for this glusterfs server vulnerability is CVE-2018-1112.
How severe is the CVE-2018-1112 vulnerability?
The CVE-2018-1112 vulnerability has a severity rating of 8.8 (High).
Which versions of glusterfs server are affected by CVE-2018-1112?
Versions 3.10.12 and 4.0.2 of glusterfs server are affected by CVE-2018-1112.
How can I fix the CVE-2018-1112 vulnerability?
To fix the CVE-2018-1112 vulnerability, update glusterfs server to version 3.10.12 or 4.0.2.
Where can I find more information about the CVE-2018-1112 vulnerability?
You can find more information about the CVE-2018-1112 vulnerability in the references provided: [link 1](http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.html), [link 2](https://access.redhat.com/articles/3422521), [link 3](https://access.redhat.com/errata/RHSA-2018:1268).