CVE-2020-15136: Fedoraproject Fedora
Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.
In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on endpoints identified in DNS SRV records for a given domain, which occurs in the discoverEndpoints function. No authentication is performed against endpoints provided in the --endpoints flag. This has been fixed in versions 3.4.10 and 3.3.23 with improved documentation and deprecation of the functionality.
Affected products
- Fedoraproject Fedora: version 32 only
- Red Hat Etcd: from 3.3.0, before 3.3.23 (fixed in 3.3.23); from 3.4.0, before 3.4.10 (fixed in 3.4.10)
Published 2020-08-06. Last modified 2026-06-17.