Incomplete Fix for Multiple Vulnerabilities in GlusterFS Allows Remote Code Execution and Denial of Service

Incomplete Fix for Multiple Vulnerabilities in GlusterFS Allows Remote Code Execution and Denial of Service

CVE-2018-14651 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of these flaws to execute arbitrary code, create arbitrary files, or cause denial of service on glusterfs server nodes via symlinks to relative paths.

Learn more about our Cis Benchmark Audit For Server Software.