Description
The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volumes could exploit this via the 'GF_XATTROP_ENTRY_IN_KEY' xattrop to create arbitrary, empty files on the target server.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2806-1 | glusterfs security update |
EUVD |
EUVD-2018-6552 | The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volumes could exploit this via the 'GF_XATTROP_ENTRY_IN_KEY' xattrop to create arbitrary, empty files on the target server. |
Ubuntu USN |
USN-4770-1 | GlusterFS vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T09:38:13.005Z
Reserved: 2018-07-27T00:00:00.000Z
Link: CVE-2018-14654
No data.
Status : Modified
Published: 2018-10-31T19:29:00.580
Modified: 2024-11-21T03:49:31.100
Link: CVE-2018-14654
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN