CVE Vulnerabilities

CVE-2021-28235

Improper Authentication

Published: Apr 04, 2023 | Modified: Apr 11, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
9.8 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Etcd Etcd 3.4.10 (including) 3.4.10 (including)
Red Hat OpenStack Platform 16.1 RedHat etcd-0:3.3.23-14.el8ost *
Red Hat OpenStack Platform 16.2 RedHat etcd-0:3.3.23-14.el8ost *
Red Hat OpenStack Platform 17.0 RedHat etcd-0:3.4.26-1.el9ost *
Etcd Ubuntu bionic *
Etcd Ubuntu esm-apps/bionic *
Etcd Ubuntu esm-apps/focal *
Etcd Ubuntu esm-apps/jammy *
Etcd Ubuntu kinetic *
Etcd Ubuntu lunar *
Etcd Ubuntu mantic *
Etcd Ubuntu trusty *
Etcd Ubuntu upstream *
Etcd Ubuntu xenial *

Potential Mitigations

References