Improper Authentication in etcd - CVE-2018-16886
Published: June 30, 2022 / Updated: July 5, 2022
Vulnerability details
The vulnerability allows a remote user to bypass authentication process.
The vulnerability exists due to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. A remote user can authenticate as user with any valid (trusted) client certificate in a REST API request to the gRPC-gateway.
Affected software
IBM Cloud Pak for Security
QRadar Suite
IBM Edge Application Manager
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM System z (Structure A)
openSUSE Leap
Fedora
etcd (Red Hat package)
etcd
etcdctl
How to mitigate CVE-2018-16886
QRadar Suite - update to 1.10.19.0
etcd (Red Hat package) - addressed in versions 3.2.26-1.el7, 3.3.11-2.el7
etcd - addressed in versions 3.3.12-1.20190314gite1ca3b4.fc29, 3.3.12-1.20190314gite1ca3b4.fc30, 3.3.12-2.20190413gitf29b1ad.fc29, 3.3.12-3.20190413gitf29b1ad.fc29, 3.3.12-4.20190413gitf29b1ad.fc29
etcdctl - update to 3.5.12-150000.7.6.1
etcd - update to 3.5.12-150000.7.6.1
External References
- http://www.securityfocus.com/bid/106540
- https://access.redhat.com/errata/RHSA-2019:0237
- https://access.redhat.com/errata/RHSA-2019:1352
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16886
- https://github.com/etcd-io/etcd/blob/1eee465a43720d713bb69f7b7f5e120135fdb1ac/CHANGELOG-3.2.md#security-authentication
- https://github.com/etcd-io/etcd/blob/1eee465a43720d713bb69f7b7f5e120135fdb1ac/CHANGELOG-3.3.md#security-authentication
Related Security Bulletins
- Improper Authentication in CoreOS etcd
- Red Hat Enterprise Linux 7 Extras update for etcd
- Red Hat Enterprise Linux 7 Extras update for etcd
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in IBM QRadar Suite Software
- SUSE update for etcd
- Fedora 30 update for etcd
- Fedora 29 update for etcd
- Fedora 29 update for etcd
- Fedora 29 update for etcd
- Fedora 29 update for etcd