VDB
Sign up
CRITICAL9.8

GHSA-gmph-wf7j-9gcm

Etcd-io Improper Authentication vulnerability

Details

Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.

This has been fixed in v.[3.5.8](https://github.com/etcd-io/etcd/blob/main/CHANGELOG/CHANGELOG-3.5.md#etcd-server) and was also backported to [3.4](https://github.com/etcd-io/etcd/pull/15655) and [3.5](https://github.com/etcd-io/etcd/pull/15653).

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/go.etcd.io/etcd/v3

No fixed version published yet for go.etcd.io/etcd/v3 (go modules). Pin to a known-safe version or switch to an alternative.

References