Записи gluster
23 опубликованных записей вендора gluster.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation6
- CWE-400 Uncontrolled Resource Consumption2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-476 NULL Pointer Dereference2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-121 Stack-based Buffer Overflow1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
23 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2018-10907Эксплойта нет | It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fgluster · glusterfs · CWE-121 | Высокая8,8 | — | 3,4 % | 4 сент. 2018 г. |
36Наблюдать | CVE-2018-10929Эксплойта нет | A flaw was found in RPC request using gfs2_create_req in glusterfs server.gluster · glusterfs · CWE-20 | Высокая8,8 | — | 3,3 % | 4 сент. 2018 г. |
36Наблюдать | CVE-2018-14651Эксплойта нет | It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete.debian · debian linux · CWE-59 | Высокая8,8 | — | 3,2 % | 31 окт. 2018 г. |
36Наблюдать | CVE-2018-10904Эксплойта нет | It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by gluster · glusterfs · CWE-426 | Высокая8,8 | — | 3,0 % | 4 сент. 2018 г. |
36Наблюдать | CVE-2018-10928Эксплойта нет | A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside gluster · glusterfs · CWE-59 | Высокая8,8 | — | 2,7 % | 4 сент. 2018 г. |
36Наблюдать | CVE-2018-10926Эксплойта нет | A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server.gluster · glusterfs · CWE-20 | Высокая8,8 | — | 2,6 % | 4 сент. 2018 г. |
36Наблюдать | CVE-2018-1112Эксплойта нет | glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster clientgluster · glusterfs · CWE-287 | Высокая8,8 | — | 2,4 % | 25 апр. 2018 г. |
35Наблюдать | CVE-2018-10841Эксплойта нет | glusterfs is vulnerable to privilege escalation on gluster server nodes.gluster · glusterfs · CWE-288 | Высокая8,8 | — | 1,3 % | 20 июн. 2018 г. |
33Наблюдать | CVE-2018-10927Эксплойта нет | A flaw was found in RPC request using gfs3_lookup_req in glusterfs server.gluster · glusterfs · CWE-20 | Высокая8,1 | — | 2,8 % | 4 сент. 2018 г. |
33Наблюдать | CVE-2018-10923Эксплойта нет | It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node.gluster · glusterfs · CWE-20 | Высокая8,1 | — | 1,7 % | 4 сент. 2018 г. |
31Наблюдать | CVE-2018-10911Эксплойта нет | A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values.gluster · glusterfs · CWE-190 | Высокая7,5 | — | 3,1 % | 4 сент. 2018 г. |
30Наблюдать | CVE-2023-26253Эксплойта нет | In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse-bridge.c notify stack-based buffer over-read.gluster · glusterfs · CWE-125 | Высокая7,5 | — | 0,9 % | 20 февр. 2023 г. |
30Наблюдать | CVE-2022-48340Эксплойта нет | In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free.gluster · glusterfs · CWE-416 | Высокая7,5 | — | 0,9 % | 20 февр. 2023 г. |
27Наблюдать | CVE-2018-14661Эксплойта нет | It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage,gluster · glusterfs · CWE-20 | Средняя6,5 | — | 2,7 % | 31 окт. 2018 г. |
27Наблюдать | CVE-2018-14660Эксплойта нет | A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr.gluster · glusterfs · CWE-400 | Средняя6,5 | — | 2,5 % | 1 нояб. 2018 г. |
27Наблюдать | CVE-2018-10914Эксплойта нет | It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a gluster · glusterfs · CWE-476 | Средняя6,5 | — | 2,4 % | 4 сент. 2018 г. |
27Наблюдать | CVE-2018-10930Эксплойта нет | A flaw was found in RPC request using gfs3_rename_req in glusterfs server.gluster · glusterfs · CWE-20 | Средняя6,5 | — | 2,1 % | 4 сент. 2018 г. |
27Наблюдать | CVE-2018-10913Эксплойта нет | An information disclosure vulnerability was discovered in glusterfs server.gluster · glusterfs · CWE-209 | Средняя6,5 | — | 2,1 % | 4 сент. 2018 г. |
27Наблюдать | CVE-2018-10924Эксплойта нет | It was discovered that fsync(2) system call in glusterfs client code leaks memory.gluster · glusterfs · CWE-400 | Средняя6,5 | — | 1,9 % | 4 сент. 2018 г. |
21Наблюдать | CVE-2014-3619Эксплойта нет | The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000gluster · glusterfs · CWE-399 | Средняя5,0 | — | 2,7 % | 27 мар. 2015 г. |
14Наблюдать | CVE-2012-4417Эксплойта нет | GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary figluster · glusterfs · CWE-264 | Низкая3,6 | — | 0,3 % | 18 нояб. 2012 г. |
13Наблюдать | CVE-2017-15096Эксплойта нет | A flaw was found in GlusterFS in versions prior to 3.10.gluster · glusterfs · CWE-476 | Низкая3,3 | — | 0,3 % | 26 окт. 2017 г. |
8Наблюдать | CVE-2012-5635Эксплойта нет | The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitragluster · glusterfs · CWE-264 | Низкая2,1 | — | 0,3 % | 9 апр. 2013 г. |
- CVE-2018-1090736Наблюдать
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating f
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %gluster · glusterfs4 сент. 2018 г.
- CVE-2018-1092936Наблюдать
A flaw was found in RPC request using gfs2_create_req in glusterfs server.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %gluster · glusterfs4 сент. 2018 г.
- CVE-2018-1465136Наблюдать
It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %debian · debian linux31 окт. 2018 г.
- CVE-2018-1090436Наблюдать
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %gluster · glusterfs4 сент. 2018 г.
- CVE-2018-1092836Наблюдать
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %gluster · glusterfs4 сент. 2018 г.
- CVE-2018-1092636Наблюдать
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %gluster · glusterfs4 сент. 2018 г.
- CVE-2018-111236Наблюдать
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %gluster · glusterfs25 апр. 2018 г.
- CVE-2018-1084135Наблюдать
glusterfs is vulnerable to privilege escalation on gluster server nodes.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %gluster · glusterfs20 июн. 2018 г.
- CVE-2018-1092733Наблюдать
A flaw was found in RPC request using gfs3_lookup_req in glusterfs server.
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %gluster · glusterfs4 сент. 2018 г.
- CVE-2018-1092333Наблюдать
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node.
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %gluster · glusterfs4 сент. 2018 г.
- CVE-2018-1091131Наблюдать
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %gluster · glusterfs4 сент. 2018 г.
- CVE-2023-2625330Наблюдать
In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse-bridge.c notify stack-based buffer over-read.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %gluster · glusterfs20 февр. 2023 г.
- CVE-2022-4834030Наблюдать
In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %gluster · glusterfs20 февр. 2023 г.
- CVE-2018-1466127Наблюдать
It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage,
СредняяCVSS 6,5Эксплойта нетEPSS 3 %gluster · glusterfs31 окт. 2018 г.
- CVE-2018-1466027Наблюдать
A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr.
СредняяCVSS 6,5Эксплойта нетEPSS 3 %gluster · glusterfs1 нояб. 2018 г.
- CVE-2018-1091427Наблюдать
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a
СредняяCVSS 6,5Эксплойта нетEPSS 2 %gluster · glusterfs4 сент. 2018 г.
- CVE-2018-1093027Наблюдать
A flaw was found in RPC request using gfs3_rename_req in glusterfs server.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %gluster · glusterfs4 сент. 2018 г.
- CVE-2018-1091327Наблюдать
An information disclosure vulnerability was discovered in glusterfs server.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %gluster · glusterfs4 сент. 2018 г.
- CVE-2018-1092427Наблюдать
It was discovered that fsync(2) system call in glusterfs client code leaks memory.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %gluster · glusterfs4 сент. 2018 г.
- CVE-2014-361921Наблюдать
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000
СредняяCVSS 5,0Эксплойта нетEPSS 3 %gluster · glusterfs27 мар. 2015 г.
- CVE-2012-441714Наблюдать
GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary fi
НизкаяCVSS 3,6Эксплойта нетEPSS 0 %gluster · glusterfs18 нояб. 2012 г.
- CVE-2017-1509613Наблюдать
A flaw was found in GlusterFS in versions prior to 3.10.
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %gluster · glusterfs26 окт. 2017 г.
- CVE-2012-56358Наблюдать
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitra
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %gluster · glusterfs9 апр. 2013 г.