Lucene search

K
redhatRedHatRHSA-2021:0916
HistoryMar 17, 2021 - 1:32 p.m.

(RHSA-2021:0916) Moderate: Red Hat OpenStack Platform 16.1.4 (etcd) security update

2021-03-1713:32:51
access.redhat.com
57

0.003 Low

EPSS

Percentile

69.3%

A highly-available key value store for shared configuration.

Security Fix(es):

  • large slice causes panic in decodeRecord method (CVE-2020-15106)

  • DoS in wal/wal.go (CVE-2020-15112)

  • directories created via os.MkdirAll are not checked for permissions
    (CVE-2020-15113)

  • gateway can include itself as an endpoint resulting in resource
    exhaustion and leads to DoS (CVE-2020-15114)

  • improper validation of passwords allow an attacker to guess or
    brute-force userโ€™s passwords (CVE-2020-15115)

  • no authentication is performed against endpoints provided in the
    โ€“endpoints flag (CVE-2020-15136)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page listed in the References section.