Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1099

Опубликовано: 03 апр. 2018
Источник: debian

Описание

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
etcdfixed3.5.5-1experimentalpackage
etcdfixed3.4.23-1package
etcdno-dsabullseyepackage
etcdno-dsabusterpackage

Примечания

  • https://github.com/coreos/etcd/issues/9353

  • https://github.com/etcd-io/etcd/pull/9372

  • https://bugzilla.redhat.com/show_bug.cgi?id=1552717

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

CVSS3: 5
redhat
почти 8 лет назад

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

CVSS3: 5.5
nvd
почти 8 лет назад

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

CVSS3: 5.5
github
почти 4 года назад

DNS Rebinding in etcd