← Back

CVE-2018-1099

nvd nist
Published: Apr 3, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

Affected (2)

1 product
Etcd
1 product
Fedora
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.3.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 30

Timeline

No history available yet.