Vulnerability DatabaseGHSA-528j-9r78-wffx

GHSA-528j-9r78-wffx
vulnerability analysis and mitigation

Overview

A low severity vulnerability (GHSA-528j-9r78-wffx) was discovered in etcd, affecting versions <= 3.4.9, where user credentials (login and password) are stored in plaintext within Write-Ahead Logging (WAL) entries during user authentication. The vulnerability was published on August 5, 2020, and has been patched in versions 3.4.10 and 3.3.23 (GitHub Advisory).

Technical details

The vulnerability stems from the storage of authentication credentials in WAL entries as plaintext during the user authentication process. The issue was identified in the authentication flow where InternalAuthenticateRequest contained password information that was being recorded in the WAL logs (Etcd PR). The vulnerability is classified as a Data Exposure issue with a Low severity rating, primarily because it requires access to the server's WAL log files to exploit.

Impact

If the WAL log files are not properly secured, sensitive information including user credentials could be exposed to unauthorized parties. This vulnerability particularly impacts environments where physical or system-level access to etcd server storage might be compromised (GitHub Advisory).

Mitigation and workarounds

The primary mitigation is to upgrade to patched versions (3.4.10 or 3.3.23). Additionally, etcd users must ensure that the server WAL log files are properly secured as etcd doesn't encrypt key/value data stored on disk drives. The fix implemented removes the password from InternalAuthenticateRequest, preventing it from being recorded in the WAL entries (GitHub PR).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management