CVE-2020-15115: Fedoraproject Fedora

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users' passwords with little computational effort.

Affected products

  • Fedoraproject Fedora: version 32 only
  • Red Hat Etcd: from 3.3.0, before 3.3.23 (fixed in 3.3.23); from 3.4.0, before 3.4.10 (fixed in 3.4.10)

Published 2020-08-06. Last modified 2026-06-17.