Back to Vulnerability Directory
HIGHFixed upstream

CVE-2020-15113

etcd: directory permissions not checked when the directory already exists

Technology

etcd

CVSS Score

7.1 / 10.0

Affected Versions

etcd before 3.3.23, 3.4.0 to 3.4.9

Upstream Fix

3.3.23, 3.4.10

Published

August 5, 2020

OSSeva Coverage

Fixed upstream

Description

etcd creates its data directory, and the directory used for automatically generated TLS certificates, with os.MkdirAll and mode 700, which does not check or correct permissions when the directory already exists. The workaround is to make sure those directories have 700 permissions.

Upstream record: NVD · CVE.org

Is your etcd deployment affected?

If you're running etcd before 3.3.23, 3.4.0 to 3.4.9, you need this patch. Book a discovery call to get covered.