Page 2 of 11 results (0.002 seconds)

CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 1

03 Apr 2018 — A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send. Se ha encontrado un fallo de Cross-Site Request Forgery (CSRF) en etcd, en versiones 3.3.1 y anteriores. Un atacante puede configurar un sitio web que intenta enviar una petic... • https://bugzilla.redhat.com/show_bug.cgi?id=1552714 • CWE-352: Cross-Site Request Forgery (CSRF) •