Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1099

Опубликовано: 07 мар. 2018
Источник: redhat
CVSS3: 5

Описание

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

It has been discovered that etcd does not correctly restrict access to resources based on hostname. A remote attacker could perform a DNS-rebinding attack and trick the browser into sending requests to an etcd server on an internal network, bypassing the Same-Origin Policy.

Меры по смягчению последствий

Configure and enable authentication on the etcd server or secure your client connection via HTTPS.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7etcdWill not fix
Red Hat Enterprise Linux 7etcd3Will not fix
Red Hat OpenShift Enterprise 3atomic-openshiftAffected
Red Hat Storage 3etcdAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1552717etcd: DNS rebinding vulnerability in etcd server

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

CVSS3: 5.5
nvd
почти 8 лет назад

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

CVSS3: 5.5
debian
почти 8 лет назад

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attack ...

CVSS3: 5.5
github
почти 4 года назад

DNS Rebinding in etcd

5 Medium

CVSS3