Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gluster

First CVE: Nov 18, 2012Active for: 14 yearsTotal CVEs: 23
42.2
VTI Score
High

Gluster maintains GlusterFS, a distributed file-system product that serves as a storage backend in virtualization and cloud infrastructure environments. The vendor's vulnerability exposure concentrates in input validation, information disclosure, and file-access control weaknesses characteristic of network-accessible storage software, alongside lower-level issues such as NULL-pointer dereferences. Defenders should treat GlusterFS security advisories as relevant to infrastructure-layer inventory and monitor backend-network access controls, particularly in virtualized deployments where the file system underpins shared storage. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
3.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gluster over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 18, 2012
13 years ago
Most Recent CVE
Feb 21, 2023
1,250 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-14651HIGH
It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of t
Oct 31, 20188.829NONO
CVE-2018-10928HIGH
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated
Sep 4, 20188.829NONO
CVE-2018-10926HIGH
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path t
Sep 4, 20188.829NONO
CVE-2018-10907HIGH
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An
Sep 4, 20188.829NONO
CVE-2018-10904HIGH
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacke
Sep 4, 20188.829NONO
CVE-2018-10841HIGH
glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to
Jun 20, 20188.828NONO
CVE-2018-1112HIGH
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gl
Apr 25, 20188.828NONO
CVE-2018-10927HIGH
A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by
Sep 4, 20188.127NONO
CVE-2018-10923HIGH
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbi
Sep 4, 20188.127NONO
CVE-2018-10911HIGH
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations in
Sep 4, 20187.526NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
13%
30%
57%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (4.3%)
Network19 (82.6%)
Unknown3 (13.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (87.0%)
High0 (0.0%)
Unknown3 (13.0%)
User Interaction
None20 (87.0%)
Unknown3 (13.0%)
Required0 (0.0%)
Privileges Required
Low17 (73.9%)
High0 (0.0%)
None3 (13.0%)
Unknown3 (13.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gluster.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gluster — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gluster's Products

View all 2 CNAs →

Top CWEs