CVE-2018-1112

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-1112
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-1112.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-1112
Related
Withdrawn
2024-05-08T06:49:57.481583Z
Published
2018-04-25T12:29:00Z
Modified
2023-11-28T15:44:38.927084Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

References

Affected packages

Git / github.com/gluster/glusterfs

Affected ranges

Type
GIT
Repo
https://github.com/gluster/glusterfs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2.*

2.0.0
2.0.0rc2
2.0.0rc3
2.0.0rc5
2.0.0rc6
2.0.0rc7
2.0.0rc8
2.0.0rc9
2.0.1

branchpoint-3.*

branchpoint-3.2

v3.*

v3.0.0
v3.0.0pre1
v3.0.1rc1
v3.0.1rc2
v3.0.1rc3
v3.0.1rc4
v3.0.1rc5
v3.1.0
v3.1.0alpha
v3.1.0beta
v3.1.0prealpha1
v3.1.0prealpha2
v3.1.0prealpha3
v3.1.0prealpha4
v3.1.0qa10
v3.1.0qa11
v3.1.0qa12
v3.1.0qa13
v3.1.0qa14
v3.1.0qa15
v3.1.0qa16
v3.1.0qa17
v3.1.0qa18
v3.1.0qa19
v3.1.0qa2
v3.1.0qa20
v3.1.0qa21
v3.1.0qa22
v3.1.0qa23
v3.1.0qa24
v3.1.0qa25
v3.1.0qa26
v3.1.0qa27
v3.1.0qa28
v3.1.0qa29
v3.1.0qa3
v3.1.0qa30
v3.1.0qa31
v3.1.0qa32
v3.1.0qa33
v3.1.0qa34
v3.1.0qa35
v3.1.0qa36
v3.1.0qa37
v3.1.0qa38
v3.1.0qa39
v3.1.0qa4
v3.1.0qa40
v3.1.0qa41
v3.1.0qa42
v3.1.0qa43
v3.1.0qa44
v3.1.0qa45
v3.1.0qa46
v3.1.0qa5
v3.1.0qa6
v3.1.0qa7
v3.1.0qa8
v3.1.0qa9
v3.1.1
v3.1.1qa1
v3.1.1qa10
v3.1.1qa11
v3.1.1qa2
v3.1.1qa3
v3.1.1qa4
v3.1.1qa5
v3.1.1qa6
v3.1.1qa7
v3.1.1qa8
v3.1.1qa9
v3.1.2
v3.1.2gsyncqa4
v3.1.2gsyncqa5
v3.1.2gsyncqa6
v3.1.2qa1
v3.1.2qa2
v3.1.2qa3
v3.1.2qa4
v3.1.3qa1
v3.1.3qa2
v3.1.3qa3
v3.1.3qa4
v3.1.3qa5
v3.10.0
v3.10.0alpha1
v3.10.0rc0
v3.10.0rc1
v3.10.1
v3.10.10
v3.10.11
v3.10.2
v3.10.3
v3.10.4
v3.10.5
v3.10.6
v3.10.7
v3.10.8
v3.10.9
v3.10dev
v3.11dev
v3.2.0
v3.2.0qa10
v3.2.0qa11
v3.2.0qa12
v3.2.0qa13
v3.2.0qa14
v3.2.0qa15
v3.2.0qa16
v3.2.0qa4
v3.2.0qa5
v3.2.0qa6
v3.2.0qa7
v3.2.0qa8
v3.2.0qa9
v3.3.0beta3
v3.3.0qa1
v3.3.0qa10
v3.3.0qa11
v3.3.0qa12
v3.3.0qa13
v3.3.0qa14
v3.3.0qa15
v3.3.0qa16
v3.3.0qa17
v3.3.0qa18
v3.3.0qa19
v3.3.0qa2
v3.3.0qa20
v3.3.0qa21
v3.3.0qa22
v3.3.0qa23
v3.3.0qa24
v3.3.0qa26
v3.3.0qa27
v3.3.0qa28
v3.3.0qa29
v3.3.0qa3
v3.3.0qa30
v3.3.0qa31
v3.3.0qa32
v3.3.0qa33
v3.3.0qa34
v3.3.0qa35
v3.3.0qa36
v3.3.0qa37
v3.3.0qa38
v3.3.0qa39
v3.3.0qa4
v3.3.0qa5
v3.3.0qa6
v3.3.0qa7
v3.3.0qa8
v3.3.0qa9
v3.3beta2
v3.4.0alpha
v3.4.0qa3
v3.4.0qa4
v3.4.0qa5
v3.4.0qa6
v3.4.0qa7
v3.4.0qa8
v3.5.0qa1
v3.5qa2
v3.7dev
v3.8dev
v3.9dev