CVE-2020-15115
06.08.2020, 22:15
etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users' passwords with little computational effort.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | etcd | 3.3.0 ≤ 𝑥 < 3.3.23 |
redhat | etcd | 3.4.0 ≤ 𝑥 < 3.4.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References