Improper Authorization in etcd - CVE-2021-28235
Published: April 26, 2023
Vulnerability identifier: #VU75512
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28235
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the system.
The vulnerability exists due to missing authorization to the "/debug" feature. A remote non-authenticated attacker can access the "/debug/requests" endpoint and gain unauthorized access to the application.
Affected software
etcd
IBM Cloud Pak for Multicloud Management
openSUSE Leap
openEuler
Ubuntu
Red Hat OpenStack for IBM Power
Red Hat OpenStack
etcd (Red Hat package)
etcd-server (Ubuntu package)
etcd-client (Ubuntu package)
etcd
etcdctl
Storage Protect Server
IBM CICS TX Advanced
IBM CICS TX Standard
IBM Cloud Pak for Multicloud Management
openSUSE Leap
openEuler
Ubuntu
Red Hat OpenStack for IBM Power
Red Hat OpenStack
etcd (Red Hat package)
etcd-server (Ubuntu package)
etcd-client (Ubuntu package)
etcd
etcdctl
Storage Protect Server
IBM CICS TX Advanced
IBM CICS TX Standard
How to mitigate CVE-2021-28235
Install updates from vendor's website.
etcd - addressed in versions 3.4.25, 3.5.8
IBM Cloud Pak for Multicloud Management - update to 2.3.8
etcd (Red Hat package) - addressed in versions 3.3.23-14.el8ost, 3.4.26-1.el9ost
etcd-server (Ubuntu package) - addressed in versions 3.3.25+dfsg-7ubuntu0.22.10.2, 3.4.23-4ubuntu0.1
etcd-client (Ubuntu package) - addressed in versions 3.3.25+dfsg-7ubuntu0.22.10.2, 3.4.23-4ubuntu0.1
etcd - addressed in versions 3.4.14-8, 3.4.14-9, 3.4.14-11
etcdctl - update to 3.5.12-150000.7.6.1
etcd - update to 3.5.12-150000.7.6.1
Storage Protect Server - update to 8.1.24
IBM CICS TX Advanced - update to 11.1.0.0 ifix6
IBM CICS TX Standard - update to 11.1.0.0 ifix6
IBM Cloud Pak for Multicloud Management - update to 2.3.8
etcd (Red Hat package) - addressed in versions 3.3.23-14.el8ost, 3.4.26-1.el9ost
etcd-server (Ubuntu package) - addressed in versions 3.3.25+dfsg-7ubuntu0.22.10.2, 3.4.23-4ubuntu0.1
etcd-client (Ubuntu package) - addressed in versions 3.3.25+dfsg-7ubuntu0.22.10.2, 3.4.23-4ubuntu0.1
etcd - addressed in versions 3.4.14-8, 3.4.14-9, 3.4.14-11
etcdctl - update to 3.5.12-150000.7.6.1
etcd - update to 3.5.12-150000.7.6.1
Storage Protect Server - update to 8.1.24
IBM CICS TX Advanced - update to 11.1.0.0 ifix6
IBM CICS TX Standard - update to 11.1.0.0 ifix6
External References
Related Security Bulletins
- Missing authorization in Etcd
- Improper authorization in IBM CICS TX Advanced
- Improper authorization in IBM CICS TX Standard
- Red Hat OpenStack Platform 16 update for etcd
- Red Hat OpenStack Platform 16 update for etcd
- Red Hat OpenStack Platform 17 update for etcd
- Ubuntu update for etcd
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- SUSE update for etcd
- Multiple vulnerabilities in IBM Storage Protect Server
- openEuler 20.03 LTS SP4 update for etcd
- openEuler 22.03 LTS SP3 update for etcd
- openEuler 22.03 LTS SP4 update for etcd