CVE-2018-1098

Severity
8.8HIGH
EPSS
0.3%
top 50.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 3
Latest updateFeb 15

Description

A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

Gogo.etcd.io/etcd/v3< 3.4.0
Debianetcd< 3.4.23-1+2
NVDredhat/etcd3.3.1
CVEListV5red_hat,_inc./etcd3.3.1 and earlier

Also affects: Fedora 30

🔴Vulnerability Details

4
GHSA
etcd Cross-site Request Forgery (CSRF)2022-02-15
OSV
etcd Cross-site Request Forgery (CSRF)2022-02-15
CVEList
CVE-2018-1098: A cross-site request forgery flaw was found in etcd 32018-04-03
OSV
CVE-2018-1098: A cross-site request forgery flaw was found in etcd 32018-04-03

📋Vendor Advisories

2
Red Hat
etcd: Cross-site request forgery via crafted local POST forms2018-03-07
Debian
CVE-2018-1098: etcd - A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attack...2018

💬Community

2
Bugzilla
CVE-2018-1098 CVE-2018-1099 etcd: various flaws [fedora-all]2018-03-07
Bugzilla
CVE-2018-1098 etcd: Cross-site request forgery via crafted local POST forms2018-03-07
CVE-2018-1098 (HIGH CVSS 8.8) | A cross-site request forgery flaw w | cvebase.io