Hide Forgot
Gluster versions 3.12.14 and 4.1.4 included incomplete fixes for the vulnerabilities, CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930 and CVE-2018-10926. All five vulnerabilities remain exploitable via symlinks pointing to relative paths. A remote authenticated attacker could exploit one of these vulnerabilities to force a server to resolve target paths and achieve a maximum impact of arbitrary code execution.
Acknowledgments: Name: Michael Hanselmann (hansmi.ch)
Statement: This issue did not affect Red Hat Enterprise Linux 6 and 7 as the flaw is present in glusterfs-server, which is not shipped there.
This issue has been addressed in the following products: Red Hat Gluster Storage 3.4 for RHEL 6 Native Client for RHEL 6 for Red Hat Storage Via RHSA-2018:3431 https://access.redhat.com/errata/RHSA-2018:3431
This issue has been addressed in the following products: Red Hat Gluster Storage 3.4 for RHEL 7 Native Client for RHEL 7 for Red Hat Storage Via RHSA-2018:3432 https://access.redhat.com/errata/RHSA-2018:3432
Created glusterfs tracking bugs for this issue: Affects: fedora-all [bug 1644730]
Can you share information on the fixing commit(s) for the CVE-2018-14651 issue (and in the other bugs respectively)?
Redirecting needinfo to Siddharth.
upstream fix: https://review.gluster.org/#/c/glusterfs/+/21527/