glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.
2018-04-25T12:29:00.213
2024-11-21T03:59:12.377
Modified
CVSSv3.0: 8.0 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gluster | glusterfs | < 3.10.12 | Yes |
Application | gluster | glusterfs | 4.0.2 | Yes |