UBUNTU-CVE-2020-15113
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-15113
UBUNTU-CVE-2020-15113
Summary:
Details: In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the os.MkdirAll. This function does not perform any permission checks when a given directory path exists already. A possible workaround is to ensure the directories have the desired permission (700).
References: https://ubuntu.com/security/CVE-2020-15113, https://github.com/etcd-io/etcd/security/advisories/GHSA-chh6-ppwq-jh92, https://ubuntu.com/security/notices/USN-5628-1, https://ubuntu.com/security/notices/USN-5628-2, https://www.cve.org/CVERecord?id=CVE-2020-15113
Affected packages
Package
Name: etcd
Purl: pkg:deb/ubuntu/etcd?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
