CVE-2020-15136
Last modified
CVE-2020-15136 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on endpoints identified in DNS SRV records for a given domain, which occurs in the discoverEndpoints function. EPSS estimates a 1.64% chance of exploitation in the next 30 days.
Description
In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on endpoints identified in DNS SRV records for a given domain, which occurs in the discoverEndpoints function. No authentication is performed against endpoints provided in the --endpoints flag. This has been fixed in versions 3.4.10 and 3.3.23 with improved documentation and deprecation of the functionality.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Etcd | >= 3.3.0, < 3.3.23 |
| Redhat | Etcd | >= 3.4.0, < 3.4.10 |
| Fedoraproject | Fedora | 32 |
References
- https://github.com/etcd-io/etcd/security/advisories/GHSA-wr2v-9rpq-c35qThird Party Advisory
- https://github.com/etcd-io/etcd/security/advisories/GHSA-wr2v-9rpq-c35qThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-15136?
How severe is CVE-2020-15136?
How do I fix CVE-2020-15136?
Are you affected by CVE-2020-15136?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
