CVE Vulnerabilities

CVE-2018-1088

Incorrect Privilege Assignment

Published: Apr 18, 2018 | Modified: Feb 13, 2023
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Enterprise_linux_server Redhat 7.0 7.0
Enterprise_linux_server Redhat 6.0 6.0
Virtualization_host Redhat 4.0 4.0
Virtualization Redhat 4.0 4.0
Gluster_storage Redhat 3.0 3.13.2

Potential Mitigations

References