cbcvebase.
CVE-2018-1098
published 2018-04-03

CVE-2018-1098: A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server…

high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianetcd< etcd 3.4.23-1 (bookworm)etcd 3.4.23-1 (bookworm)
etcdetcd>= 0 < 3.4.23-13.4.23-1
etcdetcd>= 0 < 3.4.23-13.4.23-1
etcdetcd>= 0 < 3.4.23-13.4.23-1
fedoraprojectfedora
go.etcd.ioetcd_v3>= 0 < 3.4.03.4.0
red_hat_incetcd
redhatetcd<= 3.3.1

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH