Lucene search

K
redhatcveRedhat.comRH:CVE-2018-1099
HistoryApr 03, 2018 - 2:50 p.m.

CVE-2018-1099

2018-04-0314:50:01
redhat.com
access.redhat.com
17

0.001 Low

EPSS

Percentile

29.7%

It has been discovered that etcd does not correctly restrict access to resources based on hostname. A remote attacker could perform a DNS-rebinding attack and trick the browser into sending requests to an etcd server on an internal network, bypassing the Same-Origin Policy.

Mitigation

Configure and enable authentication on the etcd server or secure your client connection via HTTPS.