gluster records
23 published records for vendor gluster.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation6
- CWE-400 Uncontrolled Resource Consumption2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-476 NULL Pointer Dereference2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-121 Stack-based Buffer Overflow1
The weakness classes this vendor ships most often: where to look.
CWEAll records
23 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2018-10907No exploit | It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fgluster · glusterfs · CWE-121 | High8.8 | — | 3.4% | Sep 4, 2018 |
36Monitor | CVE-2018-10929No exploit | A flaw was found in RPC request using gfs2_create_req in glusterfs server.gluster · glusterfs · CWE-20 | High8.8 | — | 3.3% | Sep 4, 2018 |
36Monitor | CVE-2018-14651No exploit | It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete.debian · debian linux · CWE-59 | High8.8 | — | 3.2% | Oct 31, 2018 |
36Monitor | CVE-2018-10904No exploit | It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by gluster · glusterfs · CWE-426 | High8.8 | — | 3.0% | Sep 4, 2018 |
36Monitor | CVE-2018-10928No exploit | A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside gluster · glusterfs · CWE-59 | High8.8 | — | 2.7% | Sep 4, 2018 |
36Monitor | CVE-2018-10926No exploit | A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server.gluster · glusterfs · CWE-20 | High8.8 | — | 2.6% | Sep 4, 2018 |
36Monitor | CVE-2018-1112No exploit | glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster clientgluster · glusterfs · CWE-287 | High8.8 | — | 2.4% | Apr 25, 2018 |
35Monitor | CVE-2018-10841No exploit | glusterfs is vulnerable to privilege escalation on gluster server nodes.gluster · glusterfs · CWE-288 | High8.8 | — | 1.3% | Jun 20, 2018 |
33Monitor | CVE-2018-10927No exploit | A flaw was found in RPC request using gfs3_lookup_req in glusterfs server.gluster · glusterfs · CWE-20 | High8.1 | — | 2.8% | Sep 4, 2018 |
33Monitor | CVE-2018-10923No exploit | It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node.gluster · glusterfs · CWE-20 | High8.1 | — | 1.7% | Sep 4, 2018 |
31Monitor | CVE-2018-10911No exploit | A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values.gluster · glusterfs · CWE-190 | High7.5 | — | 3.1% | Sep 4, 2018 |
30Monitor | CVE-2023-26253No exploit | In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse-bridge.c notify stack-based buffer over-read.gluster · glusterfs · CWE-125 | High7.5 | — | 0.9% | Feb 20, 2023 |
30Monitor | CVE-2022-48340No exploit | In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free.gluster · glusterfs · CWE-416 | High7.5 | — | 0.9% | Feb 20, 2023 |
27Monitor | CVE-2018-14661No exploit | It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage,gluster · glusterfs · CWE-20 | Medium6.5 | — | 2.7% | Oct 31, 2018 |
27Monitor | CVE-2018-14660No exploit | A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr.gluster · glusterfs · CWE-400 | Medium6.5 | — | 2.5% | Nov 1, 2018 |
27Monitor | CVE-2018-10914No exploit | It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a gluster · glusterfs · CWE-476 | Medium6.5 | — | 2.4% | Sep 4, 2018 |
27Monitor | CVE-2018-10930No exploit | A flaw was found in RPC request using gfs3_rename_req in glusterfs server.gluster · glusterfs · CWE-20 | Medium6.5 | — | 2.1% | Sep 4, 2018 |
27Monitor | CVE-2018-10913No exploit | An information disclosure vulnerability was discovered in glusterfs server.gluster · glusterfs · CWE-209 | Medium6.5 | — | 2.1% | Sep 4, 2018 |
27Monitor | CVE-2018-10924No exploit | It was discovered that fsync(2) system call in glusterfs client code leaks memory.gluster · glusterfs · CWE-400 | Medium6.5 | — | 1.9% | Sep 4, 2018 |
21Monitor | CVE-2014-3619No exploit | The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000gluster · glusterfs · CWE-399 | Medium5.0 | — | 2.7% | Mar 27, 2015 |
14Monitor | CVE-2012-4417No exploit | GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary figluster · glusterfs · CWE-264 | Low3.6 | — | 0.3% | Nov 18, 2012 |
13Monitor | CVE-2017-15096No exploit | A flaw was found in GlusterFS in versions prior to 3.10.gluster · glusterfs · CWE-476 | Low3.3 | — | 0.3% | Oct 26, 2017 |
8Monitor | CVE-2012-5635No exploit | The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitragluster · glusterfs · CWE-264 | Low2.1 | — | 0.3% | Apr 9, 2013 |
- CVE-2018-1090736Monitor
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating f
HighCVSS 8.8No exploitEPSS 3%gluster · glusterfsSep 4, 2018
- CVE-2018-1092936Monitor
A flaw was found in RPC request using gfs2_create_req in glusterfs server.
HighCVSS 8.8No exploitEPSS 3%gluster · glusterfsSep 4, 2018
- CVE-2018-1465136Monitor
It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete.
HighCVSS 8.8No exploitEPSS 3%debian · debian linuxOct 31, 2018
- CVE-2018-1090436Monitor
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by
HighCVSS 8.8No exploitEPSS 3%gluster · glusterfsSep 4, 2018
- CVE-2018-1092836Monitor
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside
HighCVSS 8.8No exploitEPSS 3%gluster · glusterfsSep 4, 2018
- CVE-2018-1092636Monitor
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server.
HighCVSS 8.8No exploitEPSS 3%gluster · glusterfsSep 4, 2018
- CVE-2018-111236Monitor
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client
HighCVSS 8.8No exploitEPSS 2%gluster · glusterfsApr 25, 2018
- CVE-2018-1084135Monitor
glusterfs is vulnerable to privilege escalation on gluster server nodes.
HighCVSS 8.8No exploitEPSS 1%gluster · glusterfsJun 20, 2018
- CVE-2018-1092733Monitor
A flaw was found in RPC request using gfs3_lookup_req in glusterfs server.
HighCVSS 8.1No exploitEPSS 3%gluster · glusterfsSep 4, 2018
- CVE-2018-1092333Monitor
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node.
HighCVSS 8.1No exploitEPSS 2%gluster · glusterfsSep 4, 2018
- CVE-2018-1091131Monitor
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values.
HighCVSS 7.5No exploitEPSS 3%gluster · glusterfsSep 4, 2018
- CVE-2023-2625330Monitor
In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse-bridge.c notify stack-based buffer over-read.
HighCVSS 7.5No exploitEPSS 1%gluster · glusterfsFeb 20, 2023
- CVE-2022-4834030Monitor
In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free.
HighCVSS 7.5No exploitEPSS 1%gluster · glusterfsFeb 20, 2023
- CVE-2018-1466127Monitor
It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage,
MediumCVSS 6.5No exploitEPSS 3%gluster · glusterfsOct 31, 2018
- CVE-2018-1466027Monitor
A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr.
MediumCVSS 6.5No exploitEPSS 3%gluster · glusterfsNov 1, 2018
- CVE-2018-1091427Monitor
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a
MediumCVSS 6.5No exploitEPSS 2%gluster · glusterfsSep 4, 2018
- CVE-2018-1093027Monitor
A flaw was found in RPC request using gfs3_rename_req in glusterfs server.
MediumCVSS 6.5No exploitEPSS 2%gluster · glusterfsSep 4, 2018
- CVE-2018-1091327Monitor
An information disclosure vulnerability was discovered in glusterfs server.
MediumCVSS 6.5No exploitEPSS 2%gluster · glusterfsSep 4, 2018
- CVE-2018-1092427Monitor
It was discovered that fsync(2) system call in glusterfs client code leaks memory.
MediumCVSS 6.5No exploitEPSS 2%gluster · glusterfsSep 4, 2018
- CVE-2014-361921Monitor
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000
MediumCVSS 5.0No exploitEPSS 3%gluster · glusterfsMar 27, 2015
- CVE-2012-441714Monitor
GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary fi
LowCVSS 3.6No exploitEPSS 0%gluster · glusterfsNov 18, 2012
- CVE-2017-1509613Monitor
A flaw was found in GlusterFS in versions prior to 3.10.
LowCVSS 3.3No exploitEPSS 0%gluster · glusterfsOct 26, 2017
- CVE-2012-56358Monitor
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitra
LowCVSS 2.1No exploitEPSS 0%gluster · glusterfsApr 9, 2013