CVE Vulnerabilities

CVE-2018-1088

Incorrect Privilege Assignment

Published: Apr 18, 2018 | Modified: Nov 21, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8.3 IMPORTANT
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Gluster_storageRedhat3.0 (including)3.13.2 (including)
VirtualizationRedhat4.0 (including)4.0 (including)
Virtualization_hostRedhat4.0 (including)4.0 (including)
Enterprise_linux_serverRedhat6.0 (including)6.0 (including)
Enterprise_linux_serverRedhat7.0 (including)7.0 (including)
Native Client for RHEL 6 for Red Hat StorageRedHatglusterfs-0:3.8.4-54.7.el6*
Native Client for RHEL 7 for Red Hat StorageRedHatglusterfs-0:3.8.4-54.6.el7*
Red Hat Gluster Storage 3.3 for RHEL 6RedHatglusterfs-0:3.8.4-54.7.el6rhs*
Red Hat Gluster Storage 3.3 for RHEL 7RedHatglusterfs-0:3.8.4-54.6.el7rhgs*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatglusterfs-0:3.8.4-54.6.el7*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatredhat-release-virtualization-host-0:4.1-11.0.el7*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatredhat-virtualization-host-0:4.1-20180426.0*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatimgbased-0:1.0.16-0.1.el7ev*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatovirt-node-ng-0:4.2.0-0.20170814.0.el7*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatredhat-release-virtualization-host-0:4.2-3.0.el7*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatredhat-virtualization-host-0:4.2-20180508.0*
GlusterfsUbuntuartful*
GlusterfsUbuntubionic*
GlusterfsUbuntuesm-apps/bionic*
GlusterfsUbuntuesm-apps/xenial*
GlusterfsUbuntuxenial*

Potential Mitigations

References