CVE-2021-28235
Critical · CVSS 9.8etcd (etcd-io) — Authentication Bypass / Privilege Escalation via debug function (CWE-287)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-287
Description
Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
Search profile — drives PoC discovery
Symbols debug functionetcd debug endpointv3.4.10etcd-3.4.10-testtemp4cjlucyxssPR #15648etcd-io/etcd
Keywords CVE-2021-28235etcd authentication bypassetcd privilege escalationetcd debug function exploitetcd 3.4.10 vulnerabilityetcd-io PoCetcd CWE-287etcd remote privilege escalationBitnami etcd exploitetcd authentication vulnerability PoC
Versions: v3.4.10
Affected packages
| Bitnami | etcd | 3.4.10 → 3.4.11 |
References
- https://github.com/etcd-io/etcd
- https://github.com/etcd-io/etcd/pull/15648
- https://github.com/lucyxss/etcd-3.4.10-test/blob/master/temp4cj.png
- https://github.com/lucyxss/etcd-3.4.10-test/blob/master/temp4cj_2.png
- http://etcd.com
- https://github.com/etcd-io/etcd
- https://github.com/etcd-io/etcd/pull/15648
- https://github.com/lucyxss/etcd-3.4.10-test/blob/master/temp4cj.png
- https://github.com/lucyxss/etcd-3.4.10-test/blob/master/temp4cj_2.png
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z