Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. go.etcd.io/etcd/client/v3
  4. ›
  5. GMS-2022-5093

GMS-2022-5093: etcd user credentials are stored in WAL logs in plaintext

October 6, 2022

The etcd assumes that the on disk files are secure. The possible fixes have been provided, however, it is the responsibility of the etcd users to make sure that the etcd server WAL log files are secure.

References

  • github.com/advisories/GHSA-528j-9r78-wffx
  • github.com/etcd-io/etcd/security/advisories/GHSA-528j-9r78-wffx

Code Behaviors & Features

Detect and mitigate GMS-2022-5093 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 3.3.23, all versions starting from 3.4.0 before 3.4.10

Fixed versions

  • 3.3.23
  • 3.4.10

Solution

Upgrade to versions 3.3.23, 3.4.10 or above.

Source file

go/go.etcd.io/etcd/client/v3/GMS-2022-5093.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:27 +0000.