Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2018-1099

Description

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

POC

Reference

- https://github.com/coreos/etcd/issues/9353

Github

- https://github.com/ARPSyndicate/cvemon

- https://github.com/andir/nixos-issue-db-example

- https://github.com/laojianzi/laojianzi

- https://github.com/sonatype-nexus-community/nancy