Improper Preservation of Permissions in etcd
CVE-2020-15113

5.7MEDIUM

Key Information:

Vendor

Etcd-io

Status
Vendor
CVE Published:
5 August 2020

What is CVE-2020-15113?

In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the os.MkdirAll. This function does not perform any permission checks when a given directory path exists already. A possible workaround is to ensure the directories have the desired permission (700).

Affected Version(s)

etcd < 3.3.23 < 3.3.23

etcd < 3.4.10 < 3.4.10

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.