Vulnerabilities > Redhat > Etcd > 3.3.0

DATE CVE VULNERABILITY TITLE RISK
2020-08-06 CVE-2020-15136 Missing Authentication for Critical Function vulnerability in multiple products
In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records.
network
high complexity
redhat fedoraproject CWE-306
6.5
2020-08-06 CVE-2020-15114 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access.
network
low complexity
redhat fedoraproject CWE-772
7.7
2020-08-06 CVE-2020-15115 Weak Password Requirements vulnerability in multiple products
etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one.
network
low complexity
redhat fedoraproject CWE-521
7.5
2018-04-03 CVE-2018-1099 Improper Input Validation vulnerability in multiple products
DNS rebinding vulnerability found in etcd 3.3.1 and earlier.
local
low complexity
redhat fedoraproject CWE-20
5.5
2018-04-03 CVE-2018-1098 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
A cross-site request forgery flaw was found in etcd 3.3.1 and earlier.
network
low complexity
redhat fedoraproject CWE-352
8.8