An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2018:2607 | third party advisory vendor advisory |
https://review.gluster.org/#/c/glusterfs/+/21071/ | patch vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10913 | issue tracking third party advisory mitigation |
https://lists.debian.org/debian-lts-announce/2018/09/msg00021.html | third party advisory mailing list |
https://access.redhat.com/errata/RHSA-2018:2608 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2018:3470 | third party advisory vendor advisory |
https://security.gentoo.org/glsa/201904-06 | third party advisory vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.html | mailing list third party advisory vendor advisory |
https://lists.debian.org/debian-lts-announce/2021/11/msg00000.html | third party advisory mailing list |