Cross-site request forgery in etcd - CVE-2018-1098

 

Cross-site request forgery in etcd - CVE-2018-1098

Published: April 10, 2018


Vulnerability identifier: #VU11632
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1098
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to conduct cross-site request forgery attack and gain elevated privileges on the target system.

The weakness exists due to improper validation of HTTP POST requests. A remote attacker can trick the victim into visiting a specially crafted website and gain privileges of the target user.

Affected software

etcd
IBM Edge Application Manager
Fedora
IBM Watson Machine Learning Accelerator
Storage Protect Server
etcd
IBM CICS TX Advanced
IBM CICS TX Standard

How to mitigate CVE-2018-1098

Update to version 3.3.2 or later.

IBM Watson Machine Learning Accelerator - update to 2.3.9
etcd - addressed in versions 3.3.12-1.20190314gite1ca3b4.fc29, 3.3.12-1.20190314gite1ca3b4.fc30, 3.3.12-2.20190413gitf29b1ad.fc29, 3.3.12-3.20190413gitf29b1ad.fc29, 3.3.12-4.20190413gitf29b1ad.fc29
Storage Protect Server - update to 8.1.24
IBM CICS TX Advanced - update to 11.1.0.0 ifix6
IBM CICS TX Standard - update to 11.1.0.0 ifix6

External References

Related Security Bulletins