Vulnerability CVE-2018-10930: Information

Description

A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume.

Severity: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Published: Sept. 4, 2018
Modified: Dec. 10, 2021
Error type identifier: CWE-20

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
glusterfs3p83.12.15-alt0.M80P.13.12.15-alt0.M80P.1ALT-PU-2018-2615-1214712Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://review.gluster.org/#/c/glusterfs/+/21068/
  • Patch
  • Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10930
  • Issue Tracking
  • Patch
  • Third Party Advisory
RHSA-2018:2608
  • Third Party Advisory
RHSA-2018:2607
  • Third Party Advisory
[debian-lts-announce] 20180920 [SECURITY] [DLA 1510-1] glusterfs security update
  • Mailing List
  • Third Party Advisory
RHSA-2018:3470
  • Third Party Advisory
GLSA-201904-06
  • Third Party Advisory
openSUSE-SU-2020:0079
  • Mailing List
  • Third Party Advisory
[debian-lts-announce] 20211101 [SECURITY] [DLA 2806-1] glusterfs security update
  • Mailing List
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:gluster:glusterfs:*:*:*:*:*:*:*:*
      Start including
      3.12
      End excliding
      3.12.14

      cpe:2.3:a:gluster:glusterfs:*:*:*:*:*:*:*:*
      Start including
      4.1
      End excliding
      4.1.4

      Configuration 2

      cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:virtualization_host:4.0:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

      Configuration 5

      cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*