Skip to content
etcdGHSA-chh6-ppwq-jh92

Improper Preservation of Permissions in etcd

Medium5.7CVE-2020-15113 · Published Jan 30, 2024 · updated Sep 10, 2026

### Vulnerability type Access Controls ### Detail etcd creates certain directory paths (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the os.MkdirAll. This function does not perform any permission checks when a given directory path exists already. ### Specific Go Package Affected github.com/etcd-io/etcd/pkg/fileutil ### Workarounds Make sure these directories have the desired permit (700). ### References Find out more on this vulnerability in the [security audit report](https://github.com/etcd-io/etcd/blob/master/security/SECURITY_AUDIT.pdf) ### For more information If you have any questions or comments about this advisory: * Contact the [etcd security committee](https://github.com/etcd-io/etcd/blob/master/security/security-release-process.md#product-security-committee-psc)

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/etcd-io/etcd
Go
>= 3.4.0-rc.0, < 3.4.103.4.10
< 3.3.233.3.23
Details and references

More etcd advisories

All etcd
Advisory
etcd Key name can be accessed via LeaseTimeToLive API
Low3.1May 12, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.