CVE Database · CVE-2018-1099
CVSS v3.1
N/A
EPSS
0.51%
Published
Apr 3, 2018
Modified
Nov 21, 2024
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).
Weaknesses (CWE)
Affected Products (2)
References (8)