VDB
Sign up
MEDIUM5.5

GHSA-wf43-55jj-vwq8

DNS Rebinding in etcd

Quick fix

GHSA-wf43-55jj-vwq8 — go.etcd.io/etcd: upgrade to the fixed version with the command below.

go get go.etcd.io/etcd@v3.4.0

Details

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/go.etcd.io/etcd
Introduced in: 0Fixed in: 3.4.0
Fixgo get go.etcd.io/etcd@v3.4.0

References