{"id":"CVE-2020-15136","aliases":["GHSA-wr2v-9rpq-c35q"],"url":"https://o3.security/vulnerability/CVE-2020-15136","summary":"Etcd Gateway TLS authentication only applies to endpoints detected in DNS SRV records","details":"In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on endpoints identified in DNS SRV records for a given domain, which occurs in the discoverEndpoints function. No authentication is performed against endpoints provided in the --endpoints flag. This has been fixed in versions 3.4.10 and 3.3.23 with improved documentation and deprecation of the functionality.","published":"2020-08-06T23:15:11.577Z","modified":"2026-07-08T05:59:29.521640001Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"go.etcd.io/etcd","fixedVersion":"3.4.10"},{"ecosystem":"Go","name":"go.etcd.io/etcd","fixedVersion":"3.3.23"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/etcd-io/etcd/blob/master/Documentation/op-guide/gateway.md"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L6B6R43Y7M3DCHWK3L3UVGE2K6WWECMP/"},{"type":"ADVISORY","url":"https://github.com/etcd-io/etcd/security/advisories/GHSA-wr2v-9rpq-c35q"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:59:29.521640001Z"}}