Back to Vulnerability Directory
HIGHFixed upstream

CVE-2020-15115

etcd: no minimum password length

Technology

etcd

CVSS Score

7.5 / 10.0

Affected Versions

etcd before 3.3.23, 3.4.0 to 3.4.9

Upstream Fix

3.3.23, 3.4.10

Published

August 6, 2020

OSSeva Coverage

Fixed upstream

Description

etcd performs no password length validation, so very short passwords, down to a single character, are accepted and can be guessed or brute-forced with little effort.

Upstream record: NVD · CVE.org

Is your etcd deployment affected?

If you're running etcd before 3.3.23, 3.4.0 to 3.4.9, you need this patch. Book a discovery call to get covered.