Description
In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0226 | In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway. |
Github GHSA |
GHSA-2xhq-gv6c-p224 | Etcd Gateway can include itself as an endpoint resulting in resource exhaustion |
Ubuntu USN |
USN-5628-1 | etcd vulnerabilities |
Ubuntu USN |
USN-5628-2 | etcd vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T13:08:21.664Z
Reserved: 2020-06-25T00:00:00.000Z
Link: CVE-2020-15114
No data.
Status : Modified
Published: 2020-08-06T23:15:11.517
Modified: 2024-11-21T05:04:50.810
Link: CVE-2020-15114
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN