CVE-2018-1112 Vulnerability Details

  /     /     /  

CVE-2018-1112 Metadata Quick Info

CVE Published: 25/04/2018 | CVE Updated: 05/08/2024 | CVE Year: 2018
Source: redhat | Vendor: unspecified | Product: glusterfs
Status : PUBLISHED

CVE-2018-1112 Description

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using \'auth.allow\' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-287
CWE Name: CWE-287
Source: unspecified

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).