CVE Vulnerabilities

CVE-2018-1112

Improper Authentication

Published: Apr 25, 2018 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8 IMPORTANT
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using auth.allow option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Glusterfs Gluster * 3.10.12 (excluding)
Glusterfs Gluster 4.0.2 (including) 4.0.2 (including)
Native Client for RHEL 6 for Red Hat Storage RedHat glusterfs-0:3.8.4-54.9.el6 *
Native Client for RHEL 7 for Red Hat Storage RedHat glusterfs-0:3.8.4-54.8.el7 *
Red Hat Gluster Storage 3.3 for RHEL 6 RedHat glusterfs-0:3.8.4-54.9.el6rhs *
Red Hat Gluster Storage 3.3 for RHEL 7 RedHat glusterfs-0:3.8.4-54.8.el7rhgs *
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 RedHat glusterfs-0:3.8.4-54.8.el7 *
Glusterfs Ubuntu artful *
Glusterfs Ubuntu bionic *
Glusterfs Ubuntu xenial *

Potential Mitigations

References