Gluster maintains GlusterFS, a distributed file-system product that serves as a storage backend in virtualization and cloud infrastructure environments. The vendor's vulnerability exposure concentrates in input validation, information disclosure, and file-access control weaknesses characteristic of network-accessible storage software, alongside lower-level issues such as NULL-pointer dereferences. Defenders should treat GlusterFS security advisories as relevant to infrastructure-layer inventory and monitor backend-network access controls, particularly in virtualized deployments where the file system underpins shared storage. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gluster over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14651HIGH It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of t | Oct 31, 2018 | 8.8 | 29 | NO | NO |
CVE-2018-10928HIGH A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated | Sep 4, 2018 | 8.8 | 29 | NO | NO |
CVE-2018-10926HIGH A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path t | Sep 4, 2018 | 8.8 | 29 | NO | NO |
CVE-2018-10907HIGH It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An | Sep 4, 2018 | 8.8 | 29 | NO | NO |
CVE-2018-10904HIGH It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacke | Sep 4, 2018 | 8.8 | 29 | NO | NO |
CVE-2018-10841HIGH glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to | Jun 20, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-1112HIGH glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gl | Apr 25, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-10927HIGH A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by | Sep 4, 2018 | 8.1 | 27 | NO | NO |
CVE-2018-10923HIGH It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbi | Sep 4, 2018 | 8.1 | 27 | NO | NO |
CVE-2018-10911HIGH A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations in | Sep 4, 2018 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gluster.
Media articles that mention a CVE ID that affects a product developed by Gluster — matched by CVE ID, not by vendor name.