CVE-2020-15136

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
06/08/2020
Last modified:
07/11/2023

Description

In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on endpoints identified in DNS SRV records for a given domain, which occurs in the discoverEndpoints function. No authentication is performed against endpoints provided in the --endpoints flag. This has been fixed in versions 3.4.10 and 3.3.23 with improved documentation and deprecation of the functionality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:etcd:*:*:*:*:*:*:*:* 3.3.0 (including) 3.3.23 (excluding)
cpe:2.3:a:redhat:etcd:*:*:*:*:*:*:*:* 3.4.0 (including) 3.4.10 (excluding)
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*