CVE-2018-14651: High severity debian linux vulnerability
Gluster versions 3.12.14 and 4.1.4 included incomplete fixes for the vulnerabilities, CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930 and CVE-2018-10926. All five vulnerabilities remain exploitable via symlinks pointing to relative paths. A remote authenticated attacker could exploit one of these vulnerabilities to force a server to resolve target paths and achieve a maximum impact of arbitrary code execution.
Other sources
It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of these flaws to execute arbitrary code, create arbitrary files, or cause denial of service on glusterfs server nodes via symlinks to relative paths.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-14651?
CVE-2018-14651 is a vulnerability that allows a remote, authenticated attacker to execute arbitrary code, create arbitrary files, or cause denial of service on glusterfs server nodes.
Who is affected by CVE-2018-14651?
This vulnerability affects systems running Gluster GlusterFS versions 3.12 to 3.12.14 and versions 4.1 to 4.1.4.
How severe is CVE-2018-14651?
CVE-2018-14651 has a severity rating of 8.8, which is classified as high.
How can I fix CVE-2018-14651?
To fix CVE-2018-14651, it is recommended to update to a version of Gluster GlusterFS that is not affected by the vulnerability.
Where can I find more information about CVE-2018-14651?
You can find more information about CVE-2018-14651 and related vulnerabilities at the following links: [link1](https://access.redhat.com/security/cve/CVE-2018-10927), [link2](https://access.redhat.com/security/cve/CVE-2018-10928), [link3](https://access.redhat.com/security/cve/CVE-2018-10929).