CVE Vulnerabilities

CVE-2018-1112

Improper Authentication

Published: Apr 25, 2018 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8 IMPORTANT
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using auth.allow option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
GlusterfsGluster*3.10.12 (excluding)
GlusterfsGluster4.0.2 (including)4.0.2 (including)
Native Client for RHEL 6 for Red Hat StorageRedHatglusterfs-0:3.8.4-54.9.el6*
Native Client for RHEL 7 for Red Hat StorageRedHatglusterfs-0:3.8.4-54.8.el7*
Red Hat Gluster Storage 3.3 for RHEL 6RedHatglusterfs-0:3.8.4-54.9.el6rhs*
Red Hat Gluster Storage 3.3 for RHEL 7RedHatglusterfs-0:3.8.4-54.8.el7rhgs*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatglusterfs-0:3.8.4-54.8.el7*
GlusterfsUbuntuartful*
GlusterfsUbuntubionic*
GlusterfsUbuntuxenial*

Potential Mitigations

References