etcd CVE-2018-16886 Authentication Bypass Vulnerability
BID:106540
CVE-2018-16886 |Info
etcd CVE-2018-16886 Authentication Bypass Vulnerability
| Bugtraq ID: | 106540 |
| Class: | Access Validation Error |
| CVE: |
CVE-2018-16886 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2019 12:00AM |
| Updated: | Jan 11 2019 12:00AM |
| Credit: | Matt Wheeler |
| Vulnerable: |
Redhat Enterprise Linux 7 etcd-io etcd 3.3.10 etcd-io etcd 3.3.9 etcd-io etcd 3.3.8 etcd-io etcd 3.3.7 etcd-io etcd 3.3.6 etcd-io etcd 3.2.25 etcd-io etcd 3.2.24 etcd-io etcd 3.2.23 etcd-io etcd 3.2.22 etcd-io etcd 3.2.21 etcd-io etcd 3.2 etcd-io etcd 3.1.20 etcd-io etcd 3.1.19 etcd-io etcd 3.1.18 etcd-io etcd 3.1.17 |
| Not Vulnerable: |
etcd-io etcd 3.3.11 |
Exploit / POC
etcd CVE-2018-16886 Authentication Bypass Vulnerability
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
References
etcd CVE-2018-16886 Authentication Bypass Vulnerability
References:
References:
- auth, etcdserver: authenticate clients based on certificate CommonName (etcd)
- CVE-2018-16886 (Red Hat Bugzilla)
- disable CommonName auth for gRPC-gateway (etcd)
- etcd Product Page (etcd)
- Bug 1651034 (CVE-2018-16886) - CVE-2018-16886 etcd: Improper Authentication in a (Red Hat Bugzilla)