Red Hat, Inc. Vulnerabilities and Affected Products
Vulnerabilities associated with etcd.
Products
Clear product- keycloak6 vulnerabilities
- 389-ds-base3 vulnerabilities
- ceph3 vulnerabilities
- Gluster Storage for RHEL 63 vulnerabilities
- postgresql3 vulnerabilities
- resteasy3 vulnerabilities
- Ansible Tower2 vulnerabilities
- etcd2 vulnerabilities
- GlusterFS2 vulnerabilities
- Moodle2 vulnerabilities
- Wildfly2 vulnerabilities
- ansible1 vulnerability
- atomic-openshift1 vulnerability
- augeas1 vulnerability
- Cairo1 vulnerability
- CloudForms1 vulnerability
- curl1 vulnerability
- cygwin1 vulnerability
- dnsdist1 vulnerability
- DPDK1 vulnerability
- EAP-51 vulnerability
- fedora-arm-installer1 vulnerability
- hawtio1 vulnerability
- hibernate-validator1 vulnerability
- HornetQ/Artemis1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-1099MEDIUM | DNS Rebinding in etcdDNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address). | CVSS5.5v3.0 | EPSS0.504% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
etcd Cross-site Request Forgery (CSRF)A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send. CWE-352Apr 3, 2018 | CVSS-v3.1 | EPSS1.25% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |