In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the os.MkdirAll. This function does not perform any permission checks when a given directory path exists already. A possible workaround is to ensure the directories have the desired permission (700).
CVSS Details
- CVSS 3.1 Base Score: 5.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade etcd | Jul 30, 2024 | Aug 5, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 5, 2020 |
| Ubuntu | — | Upgrade etcdUpgrade etcd-server (Ubuntu Pro)Upgrade etcd-clientUpgrade etcd-serverUpgrade etcd (Ubuntu Pro)Upgrade etcd-client (Ubuntu Pro) | Sep 23, 2022 | Aug 5, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 5, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub