CVE-2020-15114
published 2020-08-06CVE-2020-15114: In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to…
PriorityP340high7.7CVSS 3.1
AVNACLPRLUINSCCNINAH
EPSS
1.21%
64.9th percentile
In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | etcd | < etcd 3.3.25+dfsg-5 (bookworm) | etcd 3.3.25+dfsg-5 (bookworm) |
| etcd-io | etcd | < 3.3.23 | 3.3.23 |
| etcd-io | etcd | < 3.4.10 | 3.4.10 |
| etcd | etcd | >= 0 < 3.3.25+dfsg-5 | 3.3.25+dfsg-5 |
| etcd | etcd | >= 0 < 3.3.25+dfsg-5 | 3.3.25+dfsg-5 |
| etcd | etcd | >= 0 < 3.3.25+dfsg-5 | 3.3.25+dfsg-5 |
| etcd | etcd | >= 0 < 3.3.25+dfsg-5 | 3.3.25+dfsg-5 |
| etcd | etcd | >= 0 < 3.2.26+dfsg-6ubuntu0.1 | 3.2.26+dfsg-6ubuntu0.1 |
| etcd | etcd | >= 0 < 3.2.17+dfsg-1ubuntu0.1~esm1 | 3.2.17+dfsg-1ubuntu0.1~esm1 |
| fedoraproject | fedora | — | — |
| go.etcd.io | etcd | >= 0 < 3.3.23 | 3.3.23 |
| go.etcd.io | etcd | >= 3.4.0-rc.0 < 3.4.10 | 3.4.10 |
| msrc | cbl2_etcd_3.5.0-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| redhat | etcd | >= 3.3.0 < 3.3.23 | 3.3.23 |
| redhat | etcd | >= 3.4.0 < 3.4.10 | 3.4.10 |
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv7.7HIGH
vendor_debian7.7HIGH
vendor_msrc7.7HIGH
vendor_redhat7.7HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Etcd Gateway can include itself as an endpoint resulting in resource exhaustion
osv·2024-01-31
CVE-2020-15114 [HIGH] Etcd Gateway can include itself as an endpoint resulting in resource exhaustion
Etcd Gateway can include itself as an endpoint resulting in resource exhaustion
### Vulnerability type
Denial of Service
### Detail
The etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.
### References
Find out more on this vulnerability in the [security audit report](https://github.com/etcd-io/etcd/blob/master/security/SECURITY_AUDIT.pdf)
### For more information
If you have any questions or comments about this advisory:
* Contact the [etcd security committee](https://github.com/etcd-io/etcd/b
GHSA
Etcd Gateway can include itself as an endpoint resulting in resource exhaustion
ghsa·2024-01-31
CVE-2020-15114 [HIGH] CWE-400 Etcd Gateway can include itself as an endpoint resulting in resource exhaustion
Etcd Gateway can include itself as an endpoint resulting in resource exhaustion
### Vulnerability type
Denial of Service
### Detail
The etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.
### References
Find out more on this vulnerability in the [security audit report](https://github.com/etcd-io/etcd/blob/master/security/SECURITY_AUDIT.pdf)
### For more information
If you have any questions or comments about this advisory:
* Contact the [etcd security committee](https://github.com/etcd-io/etcd/b
OSV
etcd vulnerabilities
osv·2022-09-22·CVSS 6.5
CVE-2020-15106 [MEDIUM] etcd vulnerabilities
etcd vulnerabilities
It was discovered that etcd incorrectly handled certain specially crafted
WAL files. An attacker could possibly use this issue to cause a denial of
service. (CVE-2020-15106, CVE-2020-15112)
It was discovered that etcd incorrectly handled directory permissions when
trying to create a directory that exists already. An attacker could
possibly use this issue to obtain sensitive information. (CVE-2020-15113)
It was discovered that etcd incorrectly handled endpoint setup. An
attacker could possibly use this issue to cause a denial of
service. (CVE-2020-15114)
OSV
etcd vulnerabilities
osv·2022-09-22·CVSS 6.5
CVE-2020-15106 [MEDIUM] etcd vulnerabilities
etcd vulnerabilities
USN-5628-1 fixed vulnerabilities in etcd.
This update provides the corresponding updates for Ubuntu 18.04 ESM.
Original advisory details:
It was discovered that etcd incorrectly handled certain specially crafted
WAL files. An attacker could possibly use this issue to cause a denial of
service. (CVE-2020-15106, CVE-2020-15112)
It was discovered that etcd incorrectly handled directory permissions when
trying to create a directory that exists already. An attacker could
possibly use this issue to obtain sensitive information. (CVE-2020-15113)
It was discovered that etcd incorrectly handled endpoint setup. An
attacker could possibly use this issue to cause a denial of
service. (CVE-2020-15114)
OSV
CVE-2020-15114: In etcd before versions 3
osv·2020-08-06·CVSS 7.7
CVE-2020-15114 [HIGH] CVE-2020-15114: In etcd before versions 3
In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.
Ubuntu
etcd vulnerabilities
vendor_ubuntu·2022-09-22·CVSS 6.5
CVE-2020-15113 [MEDIUM] etcd vulnerabilities
Title: etcd vulnerabilities
Summary: Several security issues were fixed in etcd.
It was discovered that etcd incorrectly handled certain specially crafted
WAL files. An attacker could possibly use this issue to cause a denial of
service. (CVE-2020-15106, CVE-2020-15112)
It was discovered that etcd incorrectly handled directory permissions when
trying to create a directory that exists already. An attacker could
possibly use this issue to obtain sensitive information. (CVE-2020-15113)
It was discovered that etcd incorrectly handled endpoint setup. An
attacker could possibly use this issue to cause a denial of
service. (CVE-2020-15114)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
etcd vulnerabilities
vendor_ubuntu·2022-09-22·CVSS 6.5
CVE-2020-15113 [MEDIUM] etcd vulnerabilities
Title: etcd vulnerabilities
Summary: Several security issues were fixed in etcd.
USN-5628-1 fixed vulnerabilities in etcd.
This update provides the corresponding updates for Ubuntu 18.04 ESM.
Original advisory details:
It was discovered that etcd incorrectly handled certain specially crafted
WAL files. An attacker could possibly use this issue to cause a denial of
service. (CVE-2020-15106, CVE-2020-15112)
It was discovered that etcd incorrectly handled directory permissions when
trying to create a directory that exists already. An attacker could
possibly use this issue to obtain sensitive information. (CVE-2020-15113)
It was discovered that etcd incorrectly handled endpoint setup. An
attacker could possibly use this issue to cause a denial of
service. (CVE-2020-15114)
Instructions:
Microsoft
Denial of Service in etcd
vendor_msrc·2020-08-11·CVSS 7.7
CVE-2020-15114 [HIGH] CWE-772 Denial of Service in etcd
Denial of Service in etcd
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azu
Red Hat
etcd: gateway can include itself as an endpoint resulting in resource exhaustion and leads to DoS
vendor_redhat·2020-08-05·CVSS 7.7
CVE-2020-15114 [HIGH] CWE-400 etcd: gateway can include itself as an endpoint resulting in resource exhaustion and leads to DoS
etcd: gateway can include itself as an endpoint resulting in resource exhaustion and leads to DoS
In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.
A flaw was found in etcd, where the etcd gateway is a simple TCP proxy that allows basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This issue results in a denial of service since the endpoint can become stuck in a loop of requesting itself until
Debian
CVE-2020-15114: etcd - In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP prox...
vendor_debian·2020·CVSS 7.7
CVE-2020-15114 [HIGH] CVE-2020-15114: etcd - In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP prox...
In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.
Scope: local
bookworm: resolved (fixed in 3.3.25+dfsg-5)
bullseye: resolved (fixed in 3.3.25+dfsg-5)
forky: resolved (fixed in 3.3.25+dfsg-5)
sid: resolved (fixed in 3.3.25+dfsg-5)
trixie: resolved (fixed in 3.3.25+dfsg-5)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-15114 etcd: gateway can include itself as an endpoint resulting in resource exhaustion and leads to DoS [fedora-all]
bugzilla·2020-08-14·CVSS 7.7
CVE-2020-15114 [HIGH] CVE-2020-15114 etcd: gateway can include itself as an endpoint resulting in resource exhaustion and leads to DoS [fedora-all]
CVE-2020-15114 etcd: gateway can include itself as an endpoint resulting in resource exhaustion and leads to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2020-15114 etcd: gateway can include itself as an endpoint resulting in resource exhaustion and leads to DoS
bugzilla·2020-08-14·CVSS 7.7
CVE-2020-15114 [HIGH] CVE-2020-15114 etcd: gateway can include itself as an endpoint resulting in resource exhaustion and leads to DoS
CVE-2020-15114 etcd: gateway can include itself as an endpoint resulting in resource exhaustion and leads to DoS
In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.
References:
https://github.com/etcd-io/etcd/security/advisories/GHSA-2xhq-gv6c-p224
Discussion:
Created etcd tracking bugs for this issue:
Affects: fedora-all [bug 1868875]
---
External References:
https://github.com/etcd-io/etcd/security/advisories/GHSA-2xhq-gv6c-p224
---
FTR the
https://github.com/etcd-io/etcd/security/advisories/GHSA-2xhq-gv6c-p224https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L6B6R43Y7M3DCHWK3L3UVGE2K6WWECMP/https://github.com/etcd-io/etcd/security/advisories/GHSA-2xhq-gv6c-p224https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L6B6R43Y7M3DCHWK3L3UVGE2K6WWECMP/
2020-08-06
Published