Back to Vulnerability Directory
HIGHFixed upstream
CVE-2020-15113
etcd: directory permissions not checked when the directory already exists
Technology
etcd
CVSS Score
7.1 / 10.0
Affected Versions
etcd before 3.3.23, 3.4.0 to 3.4.9
Upstream Fix
3.3.23, 3.4.10
Published
August 5, 2020
OSSeva Coverage
Fixed upstream
Description
etcd creates its data directory, and the directory used for automatically generated TLS certificates, with os.MkdirAll and mode 700, which does not check or correct permissions when the directory already exists. The workaround is to make sure those directories have 700 permissions.
Is your etcd deployment affected?
If you're running etcd before 3.3.23, 3.4.0 to 3.4.9, you need this patch. Book a discovery call to get covered.