6.5
CVSSv3

CVE-2020-15136

Published: 06/08/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 4.2 | Exploitability Score: 2.2
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

In ectd prior to 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on endpoints identified in DNS SRV records for a given domain, which occurs in the discoverEndpoints function. No authentication is performed against endpoints provided in the --endpoints flag. This has been fixed in versions 3.4.10 and 3.3.23 with improved documentation and deprecation of the functionality.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat etcd

fedoraproject fedora 32

Vendor Advisories

Debian Bug report logs - #968752 CVE-2020-15136 Package: etcd; Maintainer for etcd is Debian Go Packaging Team <team+pkg-go@trackerdebianorg>; Source for etcd is src:etcd (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 20 Aug 2020 21:39:02 UTC Severity: important Tags: security ...