UBUNTU-CVE-2018-16886
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-16886
Summary:
Details: etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS certificate contains a Common Name (CN) which matches a valid RBAC username, a remote attacker may authenticate as that user with any valid (trusted) client certificate in a REST API request to the gRPC-gateway.
References: https://ubuntu.com/security/CVE-2018-16886, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16886, https://github.com/etcd-io/etcd/pull/10366, https://github.com/etcd-io/etcd/commit/bf9d0d8291dc71ecbfb2690612954e1a298154b2, https://github.com/etcd-io/etcd/commit/a9a9466fb8ba11ad7bb6a44d7446fbd072d59887, https://github.com/etcd-io/etcd/commit/99704e2a97e8710da942bdc737417fc9c9a2c03f, https://github.com/etcd-io/etcd/commit/83c051b701d33261eef91a719e4421c81b000ba4, https://github.com/etcd-io/etcd/pull/10386, https://www.cve.org/CVERecord?id=CVE-2018-16886
Affected packages
Package
Name: etcd
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu0.1+esm2?arch=source&distro=esm-apps/bionic
Affected ranges
Type: ECOSYSTEM
Events:
