Back

HIGH

etcd: Improper Authentication in auth/store.go:AuthInfoFromTLS() via gRPC-gateway

Published Jan 14, 2019

Description

etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS certificate contains a Common Name (CN) which matches a valid RBAC username, a remote attacker may authenticate as that user with any valid (trusted) client certificate in a REST API request to the gRPC-gateway.

Affected products

Remediation

Red Hat statement

OpenShift Container Platform 3.x, and 4.1 versions do not use etcd Role-based access control so they are not affected.

Red Hat mitigation

Ensure that the client server TLS certificate (specified in --cert-file argument or ETCD_CERT_FILE environment variable) does not include a CN (Common Name) field. If a Common Name field is part of this certificate, replace it with one which omits it. To check the CN field of a certificate: openssl x509 -noout -subject -in /path/to/client.crt | grep -o 'CN.*' To check if there is a username matching the CN field in the TLS client certificate: etcdctl user get <TLS client certificate CN> For more information on TLS authentication features including how client-cert-auth is enabled, refer to the etcd transport security model documentation: https://github.com/etcd-io/etcd/blob/master/Documentation/op-guide/security.md For more information on Role-based access control including how it is enabled, refer to the etcd role-based access control documentation: https://github.com/etcd-io/etcd/blob/master/Documentation/op-guide/authentication.md

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 14, 2019
Updated Aug 5, 2024
Reserved Sep 11, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 11, 2019
ENISA EUVD
Assigner redhat
Published Jan 14, 2019
Updated Aug 5, 2024
Exploited since n/a
EUVD-2022-1756 GHSA-H6XX-PMXH-3WGP