Vulnerability Description
In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are being read during consensus as an arbitrary etcd consensus participant could go down from a runtime panic when reading the entry.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Etcd | Etcd | < 3.3.23 |
| Fedoraproject | Fedora | 32 |
Related Weaknesses (CWE)
References
- https://github.com/etcd-io/etcd/security/advisories/GHSA-m332-53r6-2w93Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://github.com/etcd-io/etcd/security/advisories/GHSA-m332-53r6-2w93Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2020-15112?
CVE-2020-15112 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are be...
How severe is CVE-2020-15112?
CVE-2020-15112 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15112?
Check the references section above for vendor advisories and patch information. Affected products include: Etcd Etcd, Fedoraproject Fedora.