Medium severity6.5NVD Advisory· Published Oct 31, 2018· Updated Jun 17, 2026
CVE-2018-14654
CVE-2018-14654
Description
The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volumes could exploit this via the 'GF_XATTROP_ENTRY_IN_KEY' xattrop to create arbitrary, empty files on the target server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- The Gluster Project/glusterfsv5Range: through 4.1.4
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_virtualization:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:virtualization_host:4.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- access.redhat.com/errata/RHSA-2018:3431nvdVendor Advisory
- access.redhat.com/errata/RHSA-2018:3432nvdVendor Advisory
- access.redhat.com/errata/RHSA-2018:3470nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
- lists.debian.org/debian-lts-announce/2021/11/msg00000.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/201904-06nvdThird Party Advisory
News mentions
0No linked articles in our index yet.