Database/Control plane, storage & DevOps
GlusterFS (brick, gfs3_symlink_req): Symlink creation is not confined to the volume, so a client plants a link pointing
CVSS 8.8CVE-2018-10928Control plane, storage & DevOpscurated
Impact
Symlink creation is not confined to the volume, so a client plants a link pointing at a path on the server outside the gluster tree and then reads or writes through it. That reaches other volumes and the server's own filesystem from inside one tenant's mount.
Who can reach it
Any authenticated gluster client with a mounted volume.
What to do
Upgrade glusterfs server and restart the bricks, including the CVE-2018-14651 follow-up patch. Verify no residual symlinks pointing outside the brick roots survive the upgrade.
References
Related entries
- NetApp Clustered Data ONTAP export policy enforcement (SMBv2/SMBv3): Export policy rules marked read-only are notCVE-2018-5490 · NetApp Clustered Data ONTAP export policy enforcement (SMBv2/SMBv3)High
- Schneider Electric Data Center Expert 7.5.0 and earlier - zip upload: A crafted zip uploaded through the DCE UI canCVE-2018-7807 · Schneider Electric Data Center Expert 7.5.0 and earlier - zip uploadHigh
- CyberPower PowerPanel Business Edition 3.4.0 Agent/Center: Cross-site request forgery across all forms in the webCVE-2019-13071 · CyberPower PowerPanel Business Edition 3.4.0 Agent/CenterHigh
- Cisco Nexus 9000 ACI Mode (LLDP subsystem): A buffer overflow in the LLDP subsystem of Nexus 9000 switches in ACI modeCVE-2019-1901 · Cisco Nexus 9000 ACI Mode (LLDP subsystem)High
- IBM Spectrum Scale management GUI: Any authenticated GUI user - including a low-privilege monitoring account - runsCVE-2019-4715 · IBM Spectrum Scale management GUIHigh
- AMD ATI atillk64.sys - physical memory mapping driver: The AMD ATI atillk64.sys driver exposes routines that mapCVE-2020-12138 · AMD ATI atillk64.sys - physical memory mapping driverHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.