Описание
Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
A flaw was found in etcd, where etc-io could allow a remote attacker to gain elevated privileges on the system caused by a vulnerability in the debug function. By sending a specially crafted request, an attacker can gain elevated privileges.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Logging Subsystem for Red Hat OpenShift | openshift-logging/lokistack-gateway-rhel9 | Affected | ||
OpenShift Serverless | openshift-serverless-1/client-kn-rhel8 | Not affected | ||
Red Hat Enterprise Linux 7 | etcd | Will not fix | ||
Red Hat Enterprise Linux 7 | etcd3 | Will not fix | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-docker-builder | Affected | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-etcd | Affected | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-machine-config-operator | Affected | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-operator-sdk-rhel8 | Affected | ||
Red Hat OpenShift Container Platform 4 | openshift-security-profiles-operator-container | Affected | ||
Red Hat Storage 3 | etcd | Affected |
Показывать по
10
Дополнительная информация
Статус:
Important
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2184441etcd: Information discosure via debug function
9.8 Critical
CVSS3
Связанные уязвимости
CVSS3: 9.8
ubuntu
около 2 лет назад
Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
CVSS3: 9.8
nvd
около 2 лет назад
Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
CVSS3: 9.8
debian
около 2 лет назад
Authentication vulnerability found in Etcd-io v.3.4.10 allows remote a ...
9.8 Critical
CVSS3