CVE-2020-15113 affects etcd versions prior to 3.3.23 and 3.4.10, where directory paths created by os.MkdirAll for etcd data or TLS certificates may retain insecure permissions if the directory already exists. This vulnerability has a CVSS score of 7.1 (High), indicating a local attack vector with low complexity, requiring low privileges, and potentially leading to high confidentiality and integrity impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.3.23CPE matchmatch criteria | cpe:2.3:a:etcd:etcd:*:*:*:*:*:*:*:* | ||
>= 3.4.0, < 3.4.10CPE matchmatch criteria | cpe:2.3:a:etcd:etcd:*:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Improper Preservation of Permissions in etcd
Jan 30, 2024CVE-2020-15113
Dec 14, 2021Improper Preservation of Permissions in etcd
Aug 11, 2020etcd: directories created via os.MkdirAll are not checked for permissions
Aug 5, 2020