Skip to main content

Vendor/product archive

gluster / glusterfs CVEs

Beta · best-effort

23 CVEs tagged to gluster / glusterfs0 Critical, 13 High, 7 Medium, 3 Low, 0 Unrated.

CVE-2023-26253

Published Feb 21, 2023

In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse-bridge.c notify stack-based buffer over-read.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-48340

Published Feb 21, 2023

In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10924

Published Sep 4, 2018

It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making glu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10841

Published Jun 20, 2018

glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1112

Published Apr 25, 2018

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount g…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15096

Published Oct 26, 2017

A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3619

Published Mar 27, 2015

The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4417

Published Nov 18, 2012

GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1