DEBIAN-CVE-2020-15113
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 05 Aug 2020, 20:15
Last modified:28 Apr 2026, 20:21
Vulnerability Summary
Overall Risk (default)
medium
28/100 CVSS Score
7.1 HIGH
3.1 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
05 Aug 2020, 20:15
Published
Vulnerability first disclosed
28 Apr 2026, 20:21
Last Modified
Vulnerability information updated
Description
In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the os.MkdirAll. This function does not perform any permission checks when a given directory path exists already. A possible workaround is to ensure the directories have the desired permission (700).
CVSS Metrics
- v3.1•HIGH•Score: 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected Systems
- debian•etcd
< 3.3.25+dfsg-5 | < 3.3.25+dfsg-5 | < 3.3.25+dfsg-5 | < 3.3.25+dfsg-5