CVE-2018-1099

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:etcd:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-04-03 16:29

Updated : 2024-02-04 19:46


NVD link : CVE-2018-1099

Mitre link : CVE-2018-1099

CVE.ORG link : CVE-2018-1099


JSON object : View

Products Affected

redhat

  • etcd

fedoraproject

  • fedora
CWE
CWE-20

Improper Input Validation