Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-15113

Опубликовано: 05 авг. 2020
Источник: debian
EPSS Низкий

Описание

In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the os.MkdirAll. This function does not perform any permission checks when a given directory path exists already. A possible workaround is to ensure the directories have the desired permission (700).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
etcdfixed3.3.25+dfsg-1experimentalpackage
etcdfixed3.3.25+dfsg-5package
etcdno-dsabusterpackage

Примечания

  • https://github.com/etcd-io/etcd/security/advisories/GHSA-chh6-ppwq-jh92

EPSS

Процентиль: 5%
0.00023
Низкий

Связанные уязвимости

CVSS3: 5.7
ubuntu
больше 5 лет назад

In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the os.MkdirAll. This function does not perform any permission checks when a given directory path exists already. A possible workaround is to ensure the directories have the desired permission (700).

CVSS3: 7.1
redhat
больше 5 лет назад

In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the os.MkdirAll. This function does not perform any permission checks when a given directory path exists already. A possible workaround is to ensure the directories have the desired permission (700).

CVSS3: 5.7
nvd
больше 5 лет назад

In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the os.MkdirAll. This function does not perform any permission checks when a given directory path exists already. A possible workaround is to ensure the directories have the desired permission (700).

CVSS3: 7.1
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 5.7
github
около 2 лет назад

Improper Preservation of Permissions in etcd

EPSS

Процентиль: 5%
0.00023
Низкий