Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privileged gluster operations like adding other machines to trusted storage pool, start, stop, and delete volumes.
CVSS Information
N/A
Vulnerability Type
使用候选路径或通道进行的认证绕过
Vulnerability Title
GlusterFS 权限许可和访问控制问题漏洞
Vulnerability Description
GlusterFS是Gluster公司的Gluster的文件系统。 GlusterFS存在权限许可和访问控制问题漏洞。攻击者可借助TLS利用该漏洞将已认证的gluster客户端添加到可信的存储池并执行特权操作(例如:将其他设备添加到可信的存储池)。
CVSS Information
N/A
Vulnerability Type
N/A