First published: Wed Mar 17 2021(Updated: )
A highly-available key value store for shared configuration.<br>Security Fix(es):<br><li> large slice causes panic in decodeRecord method (CVE-2020-15106)</li> <li> DoS in wal/wal.go (CVE-2020-15112)</li> <li> directories created via os.MkdirAll are not checked for permissions</li> (CVE-2020-15113)<br><li> gateway can include itself as an endpoint resulting in resource</li> exhaustion and leads to DoS (CVE-2020-15114)<br><li> improper validation of passwords allow an attacker to guess or</li> brute-force user's passwords (CVE-2020-15115)<br><li> no authentication is performed against endpoints provided in the</li> <li>-endpoints flag (CVE-2020-15136)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/etcd | <3.3.23-1.el8 | 3.3.23-1.el8 |
redhat/etcd-debuginfo | <3.3.23-1.el8 | 3.3.23-1.el8 |
redhat/etcd-debugsource | <3.3.23-1.el8 | 3.3.23-1.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.