A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: redhat
Published: 2018-04-18T16:00:00Z
Updated: 2024-08-05T03:51:48.797Z
Reserved: 2017-12-04T00:00:00
Link: CVE-2018-1088
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2018-04-18T16:29:00.323
Modified: 2024-11-21T03:59:09.350
Link: CVE-2018-1088
 Redhat
                        Redhat