Denial of Service in etcd
CVE-2020-15114

7.7HIGH

Key Information:

Vendor

Etcd-io

Status
Vendor
CVE Published:
6 August 2020

What is CVE-2020-15114?

In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.

Affected Version(s)

etcd < 3.3.23 < 3.3.23

etcd < 3.4.10 < 3.4.10

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.