Логотип exploitDog
bind:CVE-2018-16886
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-16886

Количество 7

Количество 7

ubuntu логотип

CVE-2018-16886

около 7 лет назад

etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS certificate contains a Common Name (CN) which matches a valid RBAC username, a remote attacker may authenticate as that user with any valid (trusted) client certificate in a REST API request to the gRPC-gateway.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2018-16886

около 7 лет назад

etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS certificate contains a Common Name (CN) which matches a valid RBAC username, a remote attacker may authenticate as that user with any valid (trusted) client certificate in a REST API request to the gRPC-gateway.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2018-16886

около 7 лет назад

etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS certificate contains a Common Name (CN) which matches a valid RBAC username, a remote attacker may authenticate as that user with any valid (trusted) client certificate in a REST API request to the gRPC-gateway.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2018-16886

около 7 лет назад

etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerab ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-h6xx-pmxh-3wgp

почти 4 года назад

go.etcd.io/etcd Authentication Bypass

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2019-02944

около 7 лет назад

Уязвимость реализации функции контроля доступа на основе ролей Role Based Access Control (RBAC) хранилища параметров конфигурации Etcd, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 8.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3656-1

больше 1 года назад

Security update for etcd

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-16886

etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS certificate contains a Common Name (CN) which matches a valid RBAC username, a remote attacker may authenticate as that user with any valid (trusted) client certificate in a REST API request to the gRPC-gateway.

CVSS3: 8.1
1%
Низкий
около 7 лет назад
redhat логотип
CVE-2018-16886

etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS certificate contains a Common Name (CN) which matches a valid RBAC username, a remote attacker may authenticate as that user with any valid (trusted) client certificate in a REST API request to the gRPC-gateway.

CVSS3: 6.8
1%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-16886

etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS certificate contains a Common Name (CN) which matches a valid RBAC username, a remote attacker may authenticate as that user with any valid (trusted) client certificate in a REST API request to the gRPC-gateway.

CVSS3: 8.1
1%
Низкий
около 7 лет назад
debian логотип
CVE-2018-16886

etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerab ...

CVSS3: 8.1
1%
Низкий
около 7 лет назад
github логотип
GHSA-h6xx-pmxh-3wgp

go.etcd.io/etcd Authentication Bypass

CVSS3: 8.1
1%
Низкий
почти 4 года назад
fstec логотип
BDU:2019-02944

Уязвимость реализации функции контроля доступа на основе ролей Role Based Access Control (RBAC) хранилища параметров конфигурации Etcd, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 8.1
1%
Низкий
около 7 лет назад
suse-cvrf логотип
SUSE-SU-2024:3656-1

Security update for etcd

больше 1 года назад

Уязвимостей на страницу