{"id":"GHSA-5x4g-q5rc-36jp","aliases":["GO-2024-2527"],"url":"https://o3.security/vulnerability/GHSA-5x4g-q5rc-36jp","summary":"Etcd pkg Insecure ciphers are allowed by default","details":"### Vulnerability type\nCryptography\n\n### Detail\nThe TLS ciphers list supported by etcd contains insecure cipher suites. Users can configure the desired ciphers using the “--cipher-suites” flag, and a default list of secure cipher suites is used if empty.\n\n### Workarounds\nBy default, no action is required. If users want to specify cipher suites using the '--cipher-suites' flag, they should try not to specify insecure cipher suites. Please refer to the [security documentation](https://etcd.io/docs/v3.4/op-guide/security/).\n\n### References\nFind out more on this vulnerability in the [security audit report](https://github.com/etcd-io/etcd/blob/main/security/SECURITY_AUDIT.pdf)\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Contact the [etcd security committee](https://github.com/etcd-io/etcd/blob/main/security/security-release-process.md#product-security-committee-psc)","published":"2024-02-03T00:02:58Z","modified":"2026-09-10T03:50:09.746246720Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"go.etcd.io/etcd/client/pkg/v3","fixedVersion":"3.4.10"},{"ecosystem":"Go","name":"go.etcd.io/etcd/client/pkg/v3","fixedVersion":"3.3.23"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/etcd-io/etcd/security/advisories/GHSA-5x4g-q5rc-36jp"},{"type":"PACKAGE","url":"https://github.com/etcd-io/etcd"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:09.746246720Z"}}