{"schema_version":"1.7.5","id":"CVE-2021-28235","published":"2023-04-04T15:15:08.507Z","modified":"2026-07-15T10:35:52.417492Z","aliases":["BIT-etcd-2021-28235","GHSA-gmph-wf7j-9gcm"],"related":["SUSE-SU-2024:3656-1","openSUSE-SU-2024:12896-1","openSUSE-SU-2024:13369-1","openSUSE-SU-2024:13370-1","openSUSE-SU-2024:13371-1","openSUSE-SU-2025:0003-1"],"details":"Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/etcd-io/etcd","events":[{"introduced":"18dfb9cca345bb2b2fbe73d5fc31028c2477bef1"},{"last_affected":"18dfb9cca345bb2b2fbe73d5fc31028c2477bef1"}],"database_specific":{"cpe":"cpe:2.3:a:etcd:etcd:3.4.10:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.4.10"},{"last_affected":"3.4.10"}],"source":"CPE_STRING"}}],"versions":["3.4.10","v3.4.10"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-28235.json"}}],"references":[{"type":"WEB","url":"https://github.com/lucyxss/etcd-3.4.10-test/blob/master/temp4cj.png"},{"type":"WEB","url":"https://github.com/lucyxss/etcd-3.4.10-test/blob/master/temp4cj_2.png"},{"type":"FIX","url":"https://github.com/etcd-io/etcd/pull/15648"},{"type":"PACKAGE","url":"https://github.com/etcd-io/etcd"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}