CVE-2021-28235: XSS
A flaw was found in etcd, where etc-io could allow a remote attacker to gain elevated privileges on the system caused by a vulnerability in the debug function. By sending a specially crafted request, an attacker can gain elevated privileges.
Other sources
Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/etcdto a version that resolves this vulnerability.Fixed in 0:3.3.23-14.el8 - Upgrade
Upgrade
redhat/etcdto a version that resolves this vulnerability.Fixed in 0:3.4.26-1.el9 - Upgrade
Upgrade
redhat/go.etcd.io/etcd/v3to a version that resolves this vulnerability.Fixed in 3.5.8
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-28235?
CVE-2021-28235 is an authentication vulnerability found in etcd-io v3.4.10.
How does CVE-2021-28235 impact the system?
CVE-2021-28235 allows remote attackers to escalate privilege by exploiting a vulnerability in the debug function of etcd-io v3.4.10.
What is the severity of CVE-2021-28235?
CVE-2021-28235 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2021-28235?
CVE-2021-28235 affects Etcd-io v3.4.10, go.etcd.io/etcd/v3 up to version 3.5.8, and etcd up to version 3.4.26-1.el9.
How can I fix CVE-2021-28235 vulnerability?
To fix CVE-2021-28235, update Etcd-io to version 3.5.8 or later, go.etcd.io/etcd/v3 to version 3.5.8 or later, or etcd to version 3.4.26-1.el9 or later.