Glusterfs
Vendor:
First CVE: Nov 18, 2012 · Active for 13 years
23
Total CVEs
More Total CVEs than 95% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Glusterfs over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 18, 2012
13 years ago
Most Recent CVE
Feb 21, 2023
1,249 days ago
CVE Severity & Scoring
Glusterfs23 CVEs
13%
30%
57%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (4.3%)
Network19 (82.6%)
Unknown3 (13.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (87.0%)
High0 (0.0%)
Unknown3 (13.0%)
User Interaction
None20 (87.0%)
Unknown3 (13.0%)
Required0 (0.0%)
Privileges Required
Low17 (73.9%)
High0 (0.0%)
None3 (13.0%)
Unknown3 (13.0%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14651HIGH It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of t | Oct 31, 2018 | 8.8 | 29 | NO | NO |
CVE-2018-10928HIGH A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated | Sep 4, 2018 | 8.8 | 29 | NO | NO |
CVE-2018-10926HIGH A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path t | Sep 4, 2018 | 8.8 | 29 | NO | NO |
CVE-2018-10907HIGH It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An | Sep 4, 2018 | 8.8 | 29 | NO | NO |
CVE-2018-10904HIGH It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacke | Sep 4, 2018 | 8.8 | 29 | NO | NO |
CVE-2018-10841HIGH glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to | Jun 20, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-1112HIGH glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gl | Apr 25, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-10927HIGH A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by | Sep 4, 2018 | 8.1 | 27 | NO | NO |
CVE-2018-10923HIGH It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbi | Sep 4, 2018 | 8.1 | 27 | NO | NO |
CVE-2018-10911HIGH A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations in | Sep 4, 2018 | 7.5 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Glusterfs
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.0.2 | 1 | 8.8 | 2.4% | 0 | 0 |
| 3.8.4 | 1 | 6.5 | 2.7% | 0 | 0 |
| 3.5 | 1 | 5.0 | 2.7% | 0 | 0 |
| 3.3.0 | 1 | 3.6 | 0.3% | 0 | 0 |
| 11.0 | 2 | 7.5 | 0.9% | 0 | 0 |