{"id":"CVE-2021-28235","aliases":["BIT-etcd-2021-28235","GHSA-gmph-wf7j-9gcm"],"url":"https://o3.security/vulnerability/CVE-2021-28235","summary":"Etcd-io Improper Authentication vulnerability","details":"Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.\n\nThis has been fixed in v.[3.5.8](https://github.com/etcd-io/etcd/blob/main/CHANGELOG/CHANGELOG-3.5.md#etcd-server) and was also backported to [3.4](https://github.com/etcd-io/etcd/pull/15655) and [3.5](https://github.com/etcd-io/etcd/pull/15653).","published":"2023-04-04T15:15:08.507Z","modified":"2026-07-15T10:35:52.417492Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01618,"percentile":0.74475,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"go.etcd.io/etcd/v3","fixedVersion":null}],"fix":{"url":"https://github.com/etcd-io/etcd/pull/15648","label":"etcd-io/etcd#15648"},"references":[{"type":"WEB","url":"https://github.com/lucyxss/etcd-3.4.10-test/blob/master/temp4cj.png"},{"type":"WEB","url":"https://github.com/lucyxss/etcd-3.4.10-test/blob/master/temp4cj_2.png"},{"type":"FIX","url":"https://github.com/etcd-io/etcd/pull/15648"},{"type":"PACKAGE","url":"https://github.com/etcd-io/etcd"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-28235"},{"type":"WEB","url":"http://etcd.com"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T10:35:52.417492Z"}}