Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1099

Опубликовано: 03 апр. 2018
Источник: nvd
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:etcd:*:*:*:*:*:*:*:*
Версия до 3.3.1 (включая)
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

EPSS

Процентиль: 21%
0.00067
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-20
CWE-20

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

CVSS3: 5
redhat
почти 8 лет назад

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

CVSS3: 5.5
debian
почти 8 лет назад

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attack ...

CVSS3: 5.5
github
почти 4 года назад

DNS Rebinding in etcd

EPSS

Процентиль: 21%
0.00067
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-20
CWE-20