Lucene search

K
osvGoogleOSV:GHSA-5GJM-FJ42-X983
HistoryFeb 15, 2022 - 1:57 a.m.

etcd Cross-site Request Forgery (CSRF)

2022-02-1501:57:18
Google
osv.dev
10

0.002 Low

EPSS

Percentile

59.5%

A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (canโ€™t PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.

CPENameOperatorVersion
go.etcd.io/etcd/v3lt3.4.0