CVE-2018-1098
published 2018-04-03CVE-2018-1098: A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server…
PriorityP341high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.27%
66.4th percentile
A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | etcd | < etcd 3.4.23-1 (bookworm) | etcd 3.4.23-1 (bookworm) |
| etcd | etcd | >= 0 < 3.4.23-1 | 3.4.23-1 |
| etcd | etcd | >= 0 < 3.4.23-1 | 3.4.23-1 |
| etcd | etcd | >= 0 < 3.4.23-1 | 3.4.23-1 |
| fedoraproject | fedora | — | — |
| go.etcd.io | etcd_v3 | >= 0 < 3.4.0 | 3.4.0 |
| red_hat_inc | etcd | — | — |
| redhat | etcd | <= 3.3.1 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
etcd Cross-site Request Forgery (CSRF)
ghsa·2022-02-15
CVE-2018-1098 [HIGH] CWE-352 etcd Cross-site Request Forgery (CSRF)
etcd Cross-site Request Forgery (CSRF)
A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.
OSV
etcd Cross-site Request Forgery (CSRF)
osv·2022-02-15
CVE-2018-1098 [HIGH] etcd Cross-site Request Forgery (CSRF)
etcd Cross-site Request Forgery (CSRF)
A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.
OSV
CVE-2018-1098: A cross-site request forgery flaw was found in etcd 3
osv·2018-04-03·CVSS 8.8
CVE-2018-1098 [HIGH] CVE-2018-1098: A cross-site request forgery flaw was found in etcd 3
A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.
Red Hat
etcd: Cross-site request forgery via crafted local POST forms
vendor_redhat·2018-03-07·CVSS 8.8
CVE-2018-1098 [HIGH] CWE-352 etcd: Cross-site request forgery via crafted local POST forms
etcd: Cross-site request forgery via crafted local POST forms
A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.
A cross-site request forgery flaw has been discovered in etcd. A remote attacker could set up a malicious website that execute POST requests to an etcd server to modify or add a key.
Mitigation: Configure and enable authentication on the etcd server.
Package: etcd (Red Hat Enterprise Linux 7) - Will not fix
Package: etcd3 (Red Hat Enterprise Linux 7) - Will not fix
Package: atomic-openshift (
Debian
CVE-2018-1098: etcd - A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attack...
vendor_debian·2018·CVSS 8.8
CVE-2018-1098 [HIGH] CVE-2018-1098: etcd - A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attack...
A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.
Scope: local
bookworm: resolved (fixed in 3.4.23-1)
bullseye: open
forky: resolved (fixed in 3.4.23-1)
sid: resolved (fixed in 3.4.23-1)
trixie: resolved (fixed in 3.4.23-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1098 CVE-2018-1099 etcd: various flaws [fedora-all]
bugzilla·2018-03-07·CVSS 8.8
CVE-2018-1098 [HIGH] CVE-2018-1098 CVE-2018-1099 etcd: various flaws [fedora-all]
CVE-2018-1098 CVE-2018-1099 etcd: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While
Bugzilla
CVE-2018-1098 etcd: Cross-site request forgery via crafted local POST forms
bugzilla·2018-03-07·CVSS 8.8
CVE-2018-1098 [HIGH] CVE-2018-1098 etcd: Cross-site request forgery via crafted local POST forms
CVE-2018-1098 etcd: Cross-site request forgery via crafted local POST forms
A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.
Upstream bug:
https://github.com/coreos/etcd/issues/9353
Discussion:
Created etcd tracking bugs for this issue:
Affects: fedora-all [bug 1552720]
---
Reference:
https://www.twistlock.com/2018/02/28/dear-developers-beware-dns-rebinding/
---
If etcd supports the new v3 API, the attacker can run more operations through POST, as described in the reference blog post.
---
Mitiga
https://bugzilla.redhat.com/show_bug.cgi?id=1552714https://github.com/coreos/etcd/issues/9353https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JX7QTIT465BQGRGNCE74RATRQLKT2QE4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UPGYHMSKDPW5GAMI7BEP3XQRVRLLBJKS/https://bugzilla.redhat.com/show_bug.cgi?id=1552714https://github.com/coreos/etcd/issues/9353https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JX7QTIT465BQGRGNCE74RATRQLKT2QE4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UPGYHMSKDPW5GAMI7BEP3XQRVRLLBJKS/
2018-04-03
Published