Database/Container, Kubernetes & orchestration
etcd: No password length validation permits one-character etcd passwords
CVSS 5.8CVE-2020-15115Container, Kubernetes & orchestrationcurated
Impact
No password length validation permits one-character etcd passwords
Who can reach it
Unauthenticated network brute force
What to do
Rolling etcd upgrade; move to certificate auth
References
Related entries
- etcd: LeaseTimeToLive exposes key names to a user without read permission on those keysCVE-2023-32082 · etcdLow
- etcd: Authentication flaw via the debug functionCVE-2021-28235 · etcdCritical
- etcd: Gateway can be pointed at itself, causing an infinite loop and control-plane DoSCVE-2020-15114 · etcdHigh
- etcd: Gateway TLS authentication applied only to endpoints found in DNS SRV recordsCVE-2020-15136 · etcdMedium
- Kubernetes (kube-proxy): Windows kube-proxy forwards LoadBalancer traffic to local processes on the same portCVE-2021-25736 · Kubernetes (kube-proxy)Medium
- Cilium: L3 port-range plus L7 allow combination results in over-permissive policyCVE-2024-52529 · CiliumMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.