etcd: Improper Authentication in auth/store.go:AuthInfoFromTLS() via gRPC-gateway
Published Jan 14, 2019
8.1
HIGHCVSS 3.1
EPSS 4.03%
Description
etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS certificate contains a Common Name (CN) which matches a valid RBAC username, a remote attacker may authenticate as that user with any valid (trusted) client certificate in a REST API request to the gRPC-gateway.
Affected products
-
- Version versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The etcd Project | Etcd: | n/a |
|
Configuration 1
Configuration 2
- 7.0
- 7.0
- 7.0
Configuration 3
- 30
No data.
Red Hat Enterprise Linux 7 Extras
etcd-0:3.2.26-1.el7
Fixed · RHSA-2019:1352
Red Hat Enterprise Linux 7
etcd3
Not affected
Red Hat OpenShift Container Platform 3.11
atomic-openshift
Not affected
Red Hat OpenShift Container Platform 3.11
cluster-autoscaler
Not affected
Red Hat OpenShift Container Platform 3.11
metrics-server
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-etcd-rhel9
Not affected
Red Hat Storage 3
etcd
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extras | etcd-0:3.2.26-1.el7 | Fixed | RHSA-2019:1352 |
| Red Hat Enterprise Linux 7 | etcd3 | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | cluster-autoscaler | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | metrics-server | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-etcd-rhel9 | Not affected | n/a |
| Red Hat Storage 3 | etcd | Will not fix | n/a |
go.etcd.io/etcd/v3
Go
Introduced 3.2.0 Fixed 3.2.26go.etcd.io/etcd/v3
Go
Introduced 3.3.0 Fixed 3.3.11go.etcd.io/etcd
Go
Introduced 0 Fixed 0.5.0-alpha.5.0.20190108173120-83c051b701d3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | go.etcd.io/etcd/v3 | 3.2.0 | 3.2.26 |
| Go | go.etcd.io/etcd/v3 | 3.3.0 | 3.3.11 |
| Go | go.etcd.io/etcd | 0 | 0.5.0-alpha.5.0.20190108173120-83c051b701d3 |
Remediation
Red Hat statement
OpenShift Container Platform 3.x, and 4.1 versions do not use etcd Role-based access control so they are not affected.
Red Hat mitigation
Ensure that the client server TLS certificate (specified in --cert-file argument or ETCD_CERT_FILE environment variable) does not include a CN (Common Name) field. If a Common Name field is part of this certificate, replace it with one which omits it. To check the CN field of a certificate: openssl x509 -noout -subject -in /path/to/client.crt | grep -o 'CN.*' To check if there is a username matching the CN field in the TLS client certificate: etcdctl user get <TLS client certificate CN> For more information on TLS authentication features including how client-cert-auth is enabled, refer to the etcd transport security model documentation: https://github.com/etcd-io/etcd/blob/master/Documentation/op-guide/security.md For more information on Role-based access control including how it is enabled, refer to the etcd role-based access control documentation: https://github.com/etcd-io/etcd/blob/master/Documentation/op-guide/authentication.md
References (20)
- http://www.securityfocus.com/bid/106540 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:0237 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1352 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-16886 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1651034 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16886 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1756 Advisory
- https://github.com/advisories/GHSA-h6xx-pmxh-3wgp Advisory
- https://github.com/etcd-io/etcd/blob/1eee465a43720d713bb69f7b7f5e120135fdb1ac/CHANGELOG-3.2.md#security-authentication x_refsource_MISCRelease Notes
- https://github.com/etcd-io/etcd/blob/1eee465a43720d713bb69f7b7f5e120135fdb1ac/CHANGELOG-3.3.md#security-authentication x_refsource_MISCRelease Notes
- https://github.com/etcd-io/etcd/commit/0191509637546621d6f2e18e074e955ab8ef374d
- https://github.com/etcd-io/etcd/commit/bf9d0d8291dc71ecbfb2690612954e1a298154b2
- https://github.com/etcd-io/etcd/pull/10366
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JX7QTIT465BQGRGNCE74RATRQLKT2QE4/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UPGYHMSKDPW5GAMI7BEP3XQRVRLLBJKS/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JX7QTIT465BQGRGNCE74RATRQLKT2QE4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UPGYHMSKDPW5GAMI7BEP3XQRVRLLBJKS/
- https://nvd.nist.gov/vuln/detail/CVE-2018-16886
- https://pkg.go.dev/vuln/GO-2021-0077
- https://www.cve.org/CVERecord?id=CVE-2018-16886
Change history (0)
No recorded changes yet.