Insufficient Logging in etcd - #VU130100
Published: August 5, 2020 / Updated: May 5, 2026
etcd
CoreOS
Description
The vulnerability allows a remote user to cause misleading audit logs.
The vulnerability exists due to improper logging in Authenticate endpoint when handling authentication attempts for users with CN-based authentication only. A remote user can send an authentication request to cause misleading audit logs.
The issue affects users who have no password and authenticate only through a client certificate.