PT-2022-28196 · Etcd · Etcd

Published

2022-10-06

·

Updated

2022-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions etcd (affected versions not specified)
Description The issue concerns data exposure due to the storage of user credentials in WAL entries on each user authentication. If the WAL log files are not secure, it can potentially expose sensitive information, including login and password details. The etcd server does not encrypt key/value data stored on disk drives, relying on the security of the on-disk files.
Recommendations To mitigate this issue, ensure that the etcd server WAL log files are secure, as the security of these files is the responsibility of the etcd users. Consider implementing additional security measures to protect the WAL log files and sensitive information stored within. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

GHSA-528J-9R78-WFFX

Affected Products

Etcd