Back to Vulnerability Directory
HIGHFixed upstream

CVE-2020-15114

etcd gateway: self-referencing endpoint causes denial of service

Technology

etcd

CVSS Score

7.7 / 10.0

Affected Versions

etcd before 3.3.23, 3.4.0 to 3.4.9

Upstream Fix

3.3.23, 3.4.10

Published

August 6, 2020

OSSeva Coverage

Fixed upstream

Description

The etcd gateway can be given its own address as an endpoint, after which it loops requesting itself until no file descriptors remain to accept connections. The issue was reported in the etcd security audit published in 2020.

Upstream record: NVD · CVE.org

Is your etcd deployment affected?

If you're running etcd before 3.3.23, 3.4.0 to 3.4.9, you need this patch. Book a discovery call to get covered.