Glusterfs

Vendor:

First CVE: Nov 18, 2012 · Active for 13 years

23
Total CVEs
More Total CVEs than 95% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Glusterfs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 18, 2012
13 years ago
Most Recent CVE
Feb 21, 2023
1,249 days ago

CVE Severity & Scoring

Glusterfs23 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local1 (4.3%)
Network19 (82.6%)
Unknown3 (13.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (87.0%)
High0 (0.0%)
Unknown3 (13.0%)
User Interaction
None20 (87.0%)
Unknown3 (13.0%)
Required0 (0.0%)
Privileges Required
Low17 (73.9%)
High0 (0.0%)
None3 (13.0%)
Unknown3 (13.0%)

Top CVEs

Signals from CVEs in this product scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of t
Oct 31, 20188.829NONO
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated
Sep 4, 20188.829NONO
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path t
Sep 4, 20188.829NONO
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An
Sep 4, 20188.829NONO
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacke
Sep 4, 20188.829NONO
glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to
Jun 20, 20188.828NONO
glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gl
Apr 25, 20188.828NONO
A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by
Sep 4, 20188.127NONO
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbi
Sep 4, 20188.127NONO
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations in
Sep 4, 20187.526NONO

Exploit Exposure

Signals from CVEs in this product scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (23 CVEs).

Media Mentions

Signals from CVEs in this product scope (23 CVEs).

Top CNAs Publishing CVEs For Glusterfs

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.0.218.82.4%00
3.8.416.52.7%00
3.515.02.7%00
3.3.013.60.3%00
11.027.50.9%00