PT-2022-28196 · Etcd · Etcd
Published
2022-10-06
·
Updated
2022-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
etcd (affected versions not specified)
Description
The issue concerns data exposure due to the storage of user credentials in WAL entries on each user authentication. If the WAL log files are not secure, it can potentially expose sensitive information, including login and password details. The etcd server does not encrypt key/value data stored on disk drives, relying on the security of the on-disk files.
Recommendations
To mitigate this issue, ensure that the etcd server WAL log files are secure, as the security of these files is the responsibility of the etcd users. Consider implementing additional security measures to protect the WAL log files and sensitive information stored within. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Etcd