etcd v3 Unauthenticated API
etcd's v3 API is reachable and authentication is disabled or not configured. With auth disabled, the v3 API grants full read and write access to every key in the store to anyone who can reach it.
PoC 已收录etcd
CVSS—
暂无产品描述。
共找到 4 条公开漏洞记录
etcd's v3 API is reachable and authentication is disabled or not configured. With auth disabled, the v3 API grants full read and write access to every key in the store to anyone who can reach it.
etcd's v2 API is reachable without authentication, exposing the /v2/members endpoint. This endpoint discloses the full cluster membership list, including each member's name, internal peer URLs, and client URLs, without requiring any credentials.
A Kubernetes etcd server stores the cluster secrets and configurations files. Anonymous access on etcd allows unauthenticated access the data without providing any authentication credentials.