VDB
Sign up
HIGH8.8

GHSA-5gjm-fj42-x983

etcd Cross-site Request Forgery (CSRF)

Quick fix

GHSA-5gjm-fj42-x983 — go.etcd.io/etcd/v3: upgrade to the fixed version with the command below.

go get go.etcd.io/etcd/v3@v3.4.0

Details

A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/go.etcd.io/etcd/v3
Introduced in: 0Fixed in: 3.4.0
Fixgo get go.etcd.io/etcd/v3@v3.4.0

References