Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1098

Опубликовано: 07 мар. 2018
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.

A cross-site request forgery flaw has been discovered in etcd. A remote attacker could set up a malicious website that execute POST requests to an etcd server to modify or add a key.

Меры по смягчению последствий

Configure and enable authentication on the etcd server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7etcdWill not fix
Red Hat Enterprise Linux 7etcd3Will not fix
Red Hat OpenShift Enterprise 3atomic-openshiftAffected
Red Hat Storage 3etcdWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-352
https://bugzilla.redhat.com/show_bug.cgi?id=1552714etcd: Cross-site request forgery via crafted local POST forms

EPSS

Процентиль: 67%
0.01247
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.

CVSS3: 8.8
nvd
больше 8 лет назад

A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.

CVSS3: 8.8
debian
больше 8 лет назад

A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. ...

CVSS3: 8.8
github
больше 4 лет назад

etcd Cross-site Request Forgery (CSRF)

EPSS

Процентиль: 67%
0.01247
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2018-1098