CVE-2018-16886: High severity etcd vulnerability
etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS certificate contains a Common Name (CN) which matches a valid RBAC username, a remote attacker may authenticate as that user with any valid (trusted) client certificate in a REST API request to the gRPC-gateway.
Other sources
Etcd, versions 3.2.0 through 3.2.25 and 3.3.0 through 3.3.10, are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server's TLS certificate contains a Common Name (CN) which matches a valid RBAC username, a remote attacker may authenticate as that user with any valid (trusted) client certificate in a REST API request to the gRPC-gateway.
Introduced in commit: https://github.com/etcd-io/etcd/commit/0191509637546621d6f2e18e074e955ab8ef374d
Upstream issue: https://github.com/etcd-io/etcd/pull/10366
Upstream patch: https://github.com/etcd-io/etcd/commit/bf9d0d8291dc71ecbfb2690612954e1a298154b2 https://github.com/etcd-io/etcd/commit/a9a9466fb8ba11ad7bb6a44d7446fbd072d59887 https://github.com/etcd-io/etcd/commit/99704e2a97e8710da942bdc737417fc9c9a2c03f https://github.com/etcd-io/etcd/commit/83c051b701d33261eef91a719e4421c81b000ba4
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-16886?
CVE-2018-16886 is a vulnerability in etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 that allows improper authentication when role-based access control (RBAC) is used and client-cert-auth is enabled.
How severe is CVE-2018-16886?
CVE-2018-16886 has a severity score of 8.1 (High).
Which software versions are affected by CVE-2018-16886?
etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are affected by CVE-2018-16886.
How can I fix CVE-2018-16886?
To fix CVE-2018-16886, update your etcd installation to version 3.2.26 or 3.3.11 depending on your current version.
Where can I find more information about CVE-2018-16886?
You can find more information about CVE-2018-16886 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-16886), [GitHub Pull Request](https://github.com/etcd-io/etcd/pull/10366), [GitHub Commit](https://github.com/etcd-io/etcd/commit/0191509637546621d6f2e18e074e955ab8ef374d).