CVE Published: 03/04/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: redhat |
Vendor: Red Hat, Inc. |
Product: etcd Status : PUBLISHED
CVE-2018-1098 Description
A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can\'t PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.