Improper Authorization in etcd - CVE-2021-28235

 

Improper Authorization in etcd - CVE-2021-28235

Published: April 26, 2023


Vulnerability identifier: #VU75512
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28235
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the system.

The vulnerability exists due to missing authorization to the "/debug" feature. A remote non-authenticated attacker can access the "/debug/requests" endpoint and gain unauthorized access to the application.


Affected software

etcd
IBM Cloud Pak for Multicloud Management
openSUSE Leap
openEuler
Ubuntu
Red Hat OpenStack for IBM Power
Red Hat OpenStack
etcd (Red Hat package)
etcd-server (Ubuntu package)
etcd-client (Ubuntu package)
etcd
etcdctl
Storage Protect Server
IBM CICS TX Advanced
IBM CICS TX Standard

How to mitigate CVE-2021-28235

Install updates from vendor's website.

etcd - addressed in versions 3.4.25, 3.5.8
IBM Cloud Pak for Multicloud Management - update to 2.3.8
etcd (Red Hat package) - addressed in versions 3.3.23-14.el8ost, 3.4.26-1.el9ost
etcd-server (Ubuntu package) - addressed in versions 3.3.25+dfsg-7ubuntu0.22.10.2, 3.4.23-4ubuntu0.1
etcd-client (Ubuntu package) - addressed in versions 3.3.25+dfsg-7ubuntu0.22.10.2, 3.4.23-4ubuntu0.1
etcd - addressed in versions 3.4.14-8, 3.4.14-9, 3.4.14-11
etcdctl - update to 3.5.12-150000.7.6.1
etcd - update to 3.5.12-150000.7.6.1
Storage Protect Server - update to 8.1.24
IBM CICS TX Advanced - update to 11.1.0.0 ifix6
IBM CICS TX Standard - update to 11.1.0.0 ifix6

External References

Related Security Bulletins