Improper Preservation of Permissions in etcd - CVE-2020-15113
Published: August 10, 2020 / Updated: October 19, 2022
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to software improperly sets permissions to certain directory paths in case they were previously created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients). A local user can gain unauthorized access to sensitive information on the system.
Affected software
IBM Edge Application Manager
Red Hat OpenStack
Red Hat OpenStack for IBM Power
IBM MQ Operator
Ubuntu
Fedora
IBM Watson Machine Learning Accelerator
IBM supplied MQ Advanced container images
etcd-server (Ubuntu package)
etcd-client (Ubuntu package)
etcd (Ubuntu package)
etcd (Red Hat package)
etcd
IBM CICS TX Standard
IBM CICS TX Advanced
How to mitigate CVE-2020-15113
IBM MQ Operator - addressed in versions 2.0.13, 2.4.2
IBM Watson Machine Learning Accelerator - update to 2.3.9
etcd-server (Ubuntu package) - update to 3.2.26+dfsg-6ubuntu0.1
etcd-client (Ubuntu package) - update to 3.2.26+dfsg-6ubuntu0.1
etcd (Ubuntu package) - update to 3.2.26+dfsg-6ubuntu0.1
etcd (Red Hat package) - update to 3.3.23-1.el8ost
etcd - update to 3.4.13-1.fc32
IBM supplied MQ Advanced container images - update to 9.3.0.10-r1
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5
External References
Related Security Bulletins
- Multiple vulnerabilities in etcd
- Ubuntu update for etcd
- IBM CICS TX update for golang
- Red Hat OpenStack Platform 16 update for etcd
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in IBM MQ Operator
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Fedora 32 update for etcd