Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-28235

Опубликовано: 04 апр. 2023
Источник: redhat
CVSS3: 9.8

Описание

Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.

A flaw was found in etcd, where etc-io could allow a remote attacker to gain elevated privileges on the system caused by a vulnerability in the debug function. By sending a specially crafted request, an attacker can gain elevated privileges.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/lokistack-gateway-rhel9Affected
OpenShift Serverlessopenshift-serverless-1/client-kn-rhel8Not affected
Red Hat Enterprise Linux 7etcdWill not fix
Red Hat Enterprise Linux 7etcd3Will not fix
Red Hat OpenShift Container Platform 4openshift4/ose-docker-builderAffected
Red Hat OpenShift Container Platform 4openshift4/ose-etcdAffected
Red Hat OpenShift Container Platform 4openshift4/ose-machine-config-operatorAffected
Red Hat OpenShift Container Platform 4openshift4/ose-operator-sdk-rhel8Affected
Red Hat OpenShift Container Platform 4openshift-security-profiles-operator-containerAffected
Red Hat Storage 3etcdAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2184441etcd: Information discosure via debug function

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 2 лет назад

Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.

CVSS3: 9.8
nvd
около 2 лет назад

Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.

CVSS3: 9.8
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 9.8
debian
около 2 лет назад

Authentication vulnerability found in Etcd-io v.3.4.10 allows remote a ...

CVSS3: 9.8
redos
около 1 года назад

Уязвимость etcd

9.8 Critical

CVSS3