Описание
etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users' passwords with little computational effort.
A flaw was found in etcd, where it does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This flaw allows an attacker to guess or brute-force users' passwords with little computational effort. The highest threat from this vulnerability is to confidentiality.
Отчет
Red Hat OpenShift Container Platform (RHOCP) doesn't use etcd role-based access control (rbac), instead of that, OpenShift OAuth authentication is used. Therefore, RHOCP is not affected by this vulnerability. A similar configuration is in place in Red Hat OpenStack Platform (RHOSP) as etcd does not use a password for access and instead uses a TLS certificate.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | etcd | Not affected | ||
| Red Hat Enterprise Linux 7 | etcd | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-etcd-rhel9 | Not affected | ||
| Red Hat OpenStack Platform 15 (Stein) | etcd | Fix deferred | ||
| Red Hat Storage 3 | etcd | Affected | ||
| Red Hat OpenStack Platform 16.1 | etcd | Fixed | RHSA-2021:0916 | 17.03.2021 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users' passwords with little computational effort.
etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users' passwords with little computational effort.
etcd before versions 3.3.23 and 3.4.10 does not perform any password l ...
7.5 High
CVSS3