vulnerability
etcd Unauthenticated HTTP API Leak
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
9 | (AV:N/AC:L/Au:N/C:C/I:C/A:N) | Mar 28, 2018 | Mar 28, 2018 | Apr 6, 2018 |
Severity
9
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:N)
Published
Mar 28, 2018
Added
Mar 28, 2018
Modified
Apr 6, 2018
Description
The etcd HTTP API is accessible without authentication. This can result in keys being exposed which may contain sensitive information. It will also allow a user to change and delete keys without authentication. As a result, a remote attacker can not only discern sensitive information such as usernames and passwords, but also change or delete that data.
Solution
http-etcd-unauthenticated-api-data-leak

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.