6.8 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.1 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
0.018 Low
EPSS
Percentile
88.0%
etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to
an improper authentication issue when role-based access control (RBAC) is
used and client-cert-auth is enabled. If an etcd client server TLS
certificate contains a Common Name (CN) which matches a valid RBAC
username, a remote attacker may authenticate as that user with any valid
(trusted) client certificate in a REST API request to the gRPC-gateway.
Author | Note |
---|---|
msalvatore | Introduced by https://github.com/etcd-io/etcd/commit/0191509637546621d6f2e18e074e955ab8ef374d |
bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16886
github.com/etcd-io/etcd/commit/83c051b701d33261eef91a719e4421c81b000ba4
github.com/etcd-io/etcd/commit/99704e2a97e8710da942bdc737417fc9c9a2c03f
github.com/etcd-io/etcd/commit/a9a9466fb8ba11ad7bb6a44d7446fbd072d59887
github.com/etcd-io/etcd/commit/bf9d0d8291dc71ecbfb2690612954e1a298154b2
github.com/etcd-io/etcd/pull/10366
github.com/etcd-io/etcd/pull/10386 (3.2 backport)
launchpad.net/bugs/cve/CVE-2018-16886
nvd.nist.gov/vuln/detail/CVE-2018-16886
security-tracker.debian.org/tracker/CVE-2018-16886
www.cve.org/CVERecord?id=CVE-2018-16886
6.8 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.1 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
0.018 Low
EPSS
Percentile
88.0%