CVE-2018-16886

Aliases:GHSA-h6xx-pmxh-3wgpGO-2021-0077
Modified
Published: 14 Jan 2019, 19:00
Last modified:05 Aug 2024, 10:32

Vulnerability Summary

Overall Risk (default)
medium
32/100
CVSS Score
8.1 HIGH
v3.1 (nvd)
EPSS Score
0.49% LOW
0% probability -0.27%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Jan 2019, 19:00
Published
Vulnerability first disclosed
05 Aug 2024, 10:32
Last Modified
Vulnerability information updated

Description

etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS certificate contains a Common Name (CN) which matches a valid RBAC username, a remote attacker may authenticate as that user with any valid (trusted) client certificate in a REST API request to the gRPC-gateway.

CVSS Metrics

  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v3.0MEDIUMScore: 6.8CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.49% Percentile: 66%

Techniques & Countermeasures

  • CWE-287Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Systems

  • etcdetcd

    ≥ 3.2.0, < 3.2.26 | ≥ 3.3.0, < 3.3.11

  • fedoraprojectfedora

    30

  • go.etcd.ioetcd

    < 0.5.0-alpha.5.0.20190108173120-83c051b701d3

  • go.etcd.io/etcdv3

    ≥ 3.2.0, < 3.2.26 | ≥ 3.3.0, < 3.3.11

  • redhatenterprise_linux_desktop

    7.0

  • redhatenterprise_linux_server

    7.0

  • redhatenterprise_linux_workstation

    7.0

  • the etcd projectetcd:

    versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11

References (16)