Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2020-15136

etcd gateway: TLS authentication applied only to DNS SRV endpoints

Technology

etcd

CVSS Score

6.5 / 10.0

Affected Versions

etcd before 3.3.23, 3.4.0 to 3.4.9

Upstream Fix

3.3.23, 3.4.10

Published

August 6, 2020

OSSeva Coverage

Fixed upstream

Description

When the etcd gateway starts, TLS authentication is attempted only on endpoints discovered through DNS SRV records, not on endpoints given in other ways.

Upstream record: NVD · CVE.org

Is your etcd deployment affected?

If you're running etcd before 3.3.23, 3.4.0 to 3.4.9, you need this patch. Book a discovery call to get covered.