Improper Preservation of Permissions in etcd - CVE-2020-15113

 

Improper Preservation of Permissions in etcd - CVE-2020-15113

Published: August 10, 2020 / Updated: October 19, 2022


Vulnerability identifier: #VU41647
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15113
CWE-ID: CWE-281
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to software improperly sets permissions to certain directory paths in case they were previously created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients). A local user can gain unauthorized access to sensitive information on the system.


Affected software

etcd
IBM Edge Application Manager
Red Hat OpenStack
Red Hat OpenStack for IBM Power
IBM MQ Operator
Ubuntu
Fedora
IBM Watson Machine Learning Accelerator
IBM supplied MQ Advanced container images
etcd-server (Ubuntu package)
etcd-client (Ubuntu package)
etcd (Ubuntu package)
etcd (Red Hat package)
etcd
IBM CICS TX Standard
IBM CICS TX Advanced

How to mitigate CVE-2020-15113

Install updates from vendor's website.

etcd - addressed in versions 3.3.23, 3.4.10
IBM MQ Operator - addressed in versions 2.0.13, 2.4.2
IBM Watson Machine Learning Accelerator - update to 2.3.9
etcd-server (Ubuntu package) - update to 3.2.26+dfsg-6ubuntu0.1
etcd-client (Ubuntu package) - update to 3.2.26+dfsg-6ubuntu0.1
etcd (Ubuntu package) - update to 3.2.26+dfsg-6ubuntu0.1
etcd (Red Hat package) - update to 3.3.23-1.el8ost
etcd - update to 3.4.13-1.fc32
IBM supplied MQ Advanced container images - update to 9.3.0.10-r1
IBM CICS TX Standard - update to 11.1.0.0 ifix5
IBM CICS TX Advanced - update to 11.1.0.0 ifix5

External References

Related Security Bulletins