CVE-2018-1088
HIGHGluster Storage 3.x < 3.13.2 - Privilege Escalation via Snapshot Scheduler Symlink
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-1088. PoCs published by MauroEldritch.
AI-analyzed exploit summary This repository contains a working exploit for CVE-2018-1088 and CVE-2018-1112, targeting GlusterFS. The exploit leverages improper access controls in GlusterFS's shared storage volume to escalate privileges by injecting a malicious cron job.
Description
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
Exploits (1)
This repository contains a working exploit for CVE-2018-1088 and CVE-2018-1112, targeting GlusterFS. The exploit leverages improper access controls in GlusterFS's shared storage volume to escalate privileges by injecting a malicious cron job.
References (8)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H