Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-15114

Опубликовано: 05 авг. 2020
Источник: redhat
CVSS3: 7.7

Описание

In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.

A flaw was found in etcd, where the etcd gateway is a simple TCP proxy that allows basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This issue results in a denial of service since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway. The highest threat from this vulnerability is to system availability.

Отчет

In the Red Hat OpenShift Container Platform (RHOCP), the vulnerable ectd is used in the ose-etcd-container. The etcd gateway uses version 2 API which is not used by OCP, hence the impact of this vulnerability is Low. In Red Hat OpenStack Platform (RHOSP) does not use the etcd gateway and as well its use is limited to within the internal API network, which is not accessible to any OpenStack tenants.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2etcdNot affected
Red Hat Enterprise Linux 7etcdAffected
Red Hat OpenStack Platform 15 (Stein)etcdFix deferred
Red Hat Storage 3etcdAffected
Red Hat OpenShift Container Platform 4.8openshift4/ose-etcdFixedRHSA-2021:243827.07.2021
Red Hat OpenStack Platform 16.1etcdFixedRHSA-2021:091617.03.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1868874etcd: gateway can include itself as an endpoint resulting in resource exhaustion and leads to DoS

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
больше 5 лет назад

In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.

CVSS3: 7.7
nvd
больше 5 лет назад

In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.

CVSS3: 7.7
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 7.7
debian
больше 5 лет назад

In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simpl ...

CVSS3: 7.7
github
около 2 лет назад

Etcd Gateway can include itself as an endpoint resulting in resource exhaustion

7.7 High

CVSS3