GHSA-wf43-55jj-vwq8
Dashboard / Vulnerabilities / GHSA-wf43-55jj-vwq8
Summary: DNS Rebinding in etcd
Details: DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).
References: https://nvd.nist.gov/vuln/detail/CVE-2018-1099, https://github.com/coreos/etcd/issues/9353, https://github.com/coreos/etcd/commit/a7e5790c82039945639798ae9a3289fe787f5e56, https://bugzilla.redhat.com/show_bug.cgi?id=1552717, https://lists.fedoraproject.org/archives/list/[email protected]/message/JX7QTIT465BQGRGNCE74RATRQLKT2QE4, https://lists.fedoraproject.org/archives/list/[email protected]/message/UPGYHMSKDPW5GAMI7BEP3XQRVRLLBJKS
Affected packages
Package
Name: go.etcd.io/etcd
Purl: pkg:golang/go.etcd.io/etcd
Affected ranges
Type: SEMVER
Events:
