Cross-site request forgery in etcd - CVE-2018-1098
Published: April 10, 2018
Vulnerability identifier: #VU11632
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1098
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to conduct cross-site request forgery attack and gain elevated privileges on the target system.
The weakness exists due to improper validation of HTTP POST requests. A remote attacker can trick the victim into visiting a specially crafted website and gain privileges of the target user.
The weakness exists due to improper validation of HTTP POST requests. A remote attacker can trick the victim into visiting a specially crafted website and gain privileges of the target user.
Affected software
etcd
IBM Edge Application Manager
Fedora
IBM Watson Machine Learning Accelerator
Storage Protect Server
etcd
IBM CICS TX Advanced
IBM CICS TX Standard
IBM Edge Application Manager
Fedora
IBM Watson Machine Learning Accelerator
Storage Protect Server
etcd
IBM CICS TX Advanced
IBM CICS TX Standard
How to mitigate CVE-2018-1098
Update to version 3.3.2 or later.
IBM Watson Machine Learning Accelerator - update to 2.3.9
etcd - addressed in versions 3.3.12-1.20190314gite1ca3b4.fc29, 3.3.12-1.20190314gite1ca3b4.fc30, 3.3.12-2.20190413gitf29b1ad.fc29, 3.3.12-3.20190413gitf29b1ad.fc29, 3.3.12-4.20190413gitf29b1ad.fc29
Storage Protect Server - update to 8.1.24
IBM CICS TX Advanced - update to 11.1.0.0 ifix6
IBM CICS TX Standard - update to 11.1.0.0 ifix6
etcd - addressed in versions 3.3.12-1.20190314gite1ca3b4.fc29, 3.3.12-1.20190314gite1ca3b4.fc30, 3.3.12-2.20190413gitf29b1ad.fc29, 3.3.12-3.20190413gitf29b1ad.fc29, 3.3.12-4.20190413gitf29b1ad.fc29
Storage Protect Server - update to 8.1.24
IBM CICS TX Advanced - update to 11.1.0.0 ifix6
IBM CICS TX Standard - update to 11.1.0.0 ifix6
External References
Related Security Bulletins
- Multiple vulnerabilities in CoreOS etcd
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Multiple vulnerabilities in IBM Storage Protect Server
- Fedora 30 update for etcd
- Fedora 29 update for etcd
- Fedora 29 update for etcd
- Fedora 29 update for etcd
- Fedora 29 update for etcd