Description
In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the os.MkdirAll. This function does not perform any permission checks when a given directory path exists already. A possible workaround is to ensure the directories have the desired permission (700).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0332 | In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the os.MkdirAll. This function does not perform any permission checks when a given directory path exists already. A possible workaround is to ensure the directories have the desired permission (700). |
Github GHSA |
GHSA-chh6-ppwq-jh92 | Improper Preservation of Permissions in etcd |
Ubuntu USN |
USN-5628-1 | etcd vulnerabilities |
Ubuntu USN |
USN-5628-2 | etcd vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T13:08:22.262Z
Reserved: 2020-06-25T00:00:00.000Z
Link: CVE-2020-15113
No data.
Status : Modified
Published: 2020-08-05T20:15:14.647
Modified: 2024-11-21T05:04:50.613
Link: CVE-2020-15113
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN