<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – etcd</title>
  <link>https://cvedaily.com/pages/tags/etcd.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/etcd.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – etcd</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:36 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-10533 – A flaw was found in OpenShift Container Platform. Completed pods with restartPol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10533</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10533</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10533</strong></p>
  <p>A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit this to generate a large volume of events that accumulate in etcd, causing API server performance degradation across the cluster.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10533">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6720 – When calicoctl is invoked with --log-level=info or --log-level=debug, the client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6720</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6720</guid>
    <pubDate>Thu, 28 May 2026 17:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6720</strong></p>
  <p>When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log line. The struct embeds every credential calicoctl uses to talk to the cluster — inline kubeconfig (with bearer token), Kubernetes API bearer token, etcd password, and inline PEM-encoded etcd client certificate and key. A…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6720">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-44283 – etcd is a distributed key-value store for the data of a distributed system. Prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44283</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44283</guid>
    <pubDate>Thu, 14 May 2026 18:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-44283</strong></p>
  <p>etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach le…</p>
  <p><strong>CVSS:</strong> 0.0 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44283">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42880 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42880</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42880</guid>
    <pubDate>Thu, 07 May 2026 23:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42880</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. T…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42880">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33817 – (This report has been withdrawn with reason: "Reporter and maintainer have confi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33817</guid>
    <pubDate>Mon, 06 Apr 2026 19:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33817</strong></p>
  <p>(This report has been withdrawn with reason: "Reporter and maintainer have confirmed this as false positive"). Index out-of-range when encountering a branch page with zero elements in go.etcd.io/bbolt</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33413 – etcd is a distributed key-value store for the data of a distributed system. Prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33413</guid>
    <pubDate>Thu, 26 Mar 2026 14:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33413</strong></p>
  <p>etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthorized users may bypass authentication or authorization checks and call certain etcd functions in clusters that expose the gRPC API to untrusted or partially trusted clients. In unpatched etcd clusters with etcd auth enabled, unauthorized users are able to call MemberList…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33413">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-33343 – etcd is a distributed key-value store for the data of a distributed system. Prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33343</guid>
    <pubDate>Thu, 26 Mar 2026 14:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-33343</strong></p>
  <p>etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, an authenticated user with RBAC restricted permissions on key ranges can use nested transactions to bypass all key-level authorization. This allows any authenticated user with direct access to etcd to effectively ignore all key range restrictions, accessing the entire etcd data…</p>
  <p><strong>CVSS:</strong> 0.0 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-26190 – Milvus is an open-source vector database built for generative AI applications. P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26190</guid>
    <pubDate>Fri, 13 Feb 2026 19:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-26190</strong></p>
  <p>Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable default authentication token derived from etcd.rootPath (default: by-dev), enabling arbitrary expression evaluation. The full REST API (/api/v1/*) is registered o…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58063 – CoreDNS is a DNS server that chains plugins. Starting in version 1.2.0 and prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58063</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58063</guid>
    <pubDate>Tue, 09 Sep 2025 20:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58063</strong></p>
  <p>CoreDNS is a DNS server that chains plugins. Starting in version 1.2.0 and prior to version 1.12.4, the CoreDNS etcd plugin contains a TTL confusion vulnerability where lease IDs are incorrectly used as TTL values, enabling DNS cache pinning attacks. This effectively creates a DoS condition for DNS resolution of affected services. The `TTL()` function in `plugin/etcd/etcd.go` incorrectly casts et…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-681</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58063">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-42480 – Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42480</guid>
    <pubDate>Mon, 12 Aug 2024 16:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-42480</strong></p>
  <p>Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC for etcd roles leading to some TCPs API servers being able to read, write, and delete the data of other control planes. This vulnerability is fixed in edge-24.8.2.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4438 – The etcd package distributed with the Red Hat OpenStack platform has an incomple...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4438</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4438</guid>
    <pubDate>Wed, 08 May 2024 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4438</strong></p>
  <p>The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2023-39325/CVE-2023-44487, known as Rapid Reset. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4438">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4437 – The etcd package distributed with the Red Hat OpenStack platform has an incomple...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4437</guid>
    <pubDate>Wed, 08 May 2024 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4437</strong></p>
  <p>The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2021-44716. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4436 – The etcd package distributed with the Red Hat OpenStack platform has an incomple...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4436</guid>
    <pubDate>Wed, 08 May 2024 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4436</strong></p>
  <p>The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2022-41723. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46307 – An issue was discovered in server.js in etcd-browser 87ae63d75260. By supplying ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46307</guid>
    <pubDate>Thu, 07 Dec 2023 06:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46307</strong></p>
  <p>An issue was discovered in server.js in etcd-browser 87ae63d75260. By supplying a /../../../ Directory Traversal input to the URL's GET request while connecting to the remote server port specified during setup, an attacker can retrieve local operating system files from the remote system.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5408 – A privilege escalation flaw was found in the node restriction admission plugin o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5408</guid>
    <pubDate>Thu, 02 Nov 2023 03:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5408</strong></p>
  <p>A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modifies the node role label could steer workloads from the control plane and etcd nodes onto different worker nodes and gain broader access to the cluster.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-34038 – Etcd v3.5.4 allows remote attackers to cause a denial of service via function Pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34038</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34038</guid>
    <pubDate>Tue, 22 Aug 2023 19:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-34038</strong></p>
  <p>Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor's position is that this is not a vulnerability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34038">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-32082 – etcd is a distributed key-value store for the data of a distributed system. Prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32082</guid>
    <pubDate>Thu, 11 May 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-32082</strong></p>
  <p>etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-30841 – Baremetal Operator (BMO) is a bare metal host provisioning integration for Kuber...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30841</guid>
    <pubDate>Wed, 26 Apr 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-30841</strong></p>
  <p>Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic and ironic-inspector deployed within Baremetal Operator using the included `deploy.sh` store their `.htpasswd` files as ConfigMaps instead of Secrets. This causes the plain-text username and hashed password to be readable by anyone having a cluster-wide read-access to the manageme…</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-28235 – Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28235</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28235</guid>
    <pubDate>Tue, 04 Apr 2023 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-28235</strong></p>
  <p>Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28235">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-28114 – `cilium-cli` is the command line interface to install, manage, and troubleshoot ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28114</guid>
    <pubDate>Wed, 22 Mar 2023 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-28114</strong></p>
  <p>`cilium-cli` is the command line interface to install, manage, and troubleshoot Kubernetes clusters running Cilium. Prior to version 0.13.2,`cilium-cli`, when used to configure cluster mesh functionality, can remove the enforcement of user permissions on the `etcd` store used to mirror local cluster information to remote clusters. Users who have set up cluster meshes using the Cilium Helm chart a…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-280</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0296 – The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was report...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0296</guid>
    <pubDate>Tue, 17 Jan 2023 21:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0296</strong></p>
  <p>The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the etcd components, to enable periodic health checks from kubelet, it was necessary to open up a new port (9979) on etcd grpc-proxy, hence this port might be considered as still vulnerable to the same ty…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15114 – In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP prox...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15114</guid>
    <pubDate>Thu, 06 Aug 2020 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15114</strong></p>
  <p>In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-15115 – etcd before versions 3.3.23 and 3.4.10 does not perform any password length vali...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15115</guid>
    <pubDate>Thu, 06 Aug 2020 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-15115</strong></p>
  <p>etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users' passwords with little computational effort.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-15113 – In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15113</guid>
    <pubDate>Wed, 05 Aug 2020 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-15113</strong></p>
  <p>In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the os.MkdirAll. This function does not perform any permission checks when a given directory path exists already. A possible wo…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-15112 – In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15112</guid>
    <pubDate>Wed, 05 Aug 2020 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-15112</strong></p>
  <p>In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are being read during consensus as an arbitrary etcd consensus participant could go down from a runtime panic when reading the entry.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-15106 – In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeR...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15106</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15106</guid>
    <pubDate>Wed, 05 Aug 2020 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-15106</strong></p>
  <p>In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is stored in the length field of a WAL file and no additional validation is done on this data. Therefore, it is possible to forge an extremely large frame size that can unintentionally panic at the expense of any RAFT participant trying to decode the WAL.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15106">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3786 – Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3786</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3786</guid>
    <pubDate>Wed, 24 Apr 2019 16:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3786</strong></p>
  <p>Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup scripts in BOSH. A remote authenticated malicious user can modify the metadata file of a Bosh Backup and Restore job to request extra backup files from different jobs upon restore. The exploited hooks in this metadata script were only maintained in the cfcr-etcd-release, so clusters d…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3786">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3779 – Cloud Foundry Container Runtime, versions prior to 0.29.0, deploys Kubernetes cl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3779</guid>
    <pubDate>Fri, 08 Mar 2019 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3779</strong></p>
  <p>Cloud Foundry Container Runtime, versions prior to 0.29.0, deploys Kubernetes clusters utilize the same CA (Certificate Authority) to sign and trust certs for ETCD as used by the Kubernetes API. This could allow a user authenticated with a cluster to request a signed certificate leveraging the Kubernetes CSR capability to obtain a credential that could escalate privilege access to ETCD.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-16886 – etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16886</guid>
    <pubDate>Mon, 14 Jan 2019 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-16886</strong></p>
  <p>etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS certificate contains a Common Name (CN) which matches a valid RBAC username, a remote attacker may authenticate as that user with any valid (trusted) client certificate in a REST API…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-1085 – openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1085</guid>
    <pubDate>Fri, 15 Jun 2018 13:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-1085</strong></p>
  <p>openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabled. Quotations around the values of ETCD_CLIENT_CERT_AUTH and ETCD_PEER_CLIENT_CERT_AUTH in etcd.conf result in etcd being configured to allow remote users to connect without any authentication if they can access the etcd server bound to the network…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-592</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-1099 – DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1099</guid>
    <pubDate>Tue, 03 Apr 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-1099</strong></p>
  <p>DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1098 – A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1098</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1098</guid>
    <pubDate>Tue, 03 Apr 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1098</strong></p>
  <p>A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1098">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-5305 – Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift En...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5305</guid>
    <pubDate>Fri, 06 Nov 2015 18:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-5305</strong></p>
  <p>Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a crafted object type name, which is not properly handled before passing it to etcd.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5305">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
