GHSA-m332-53r6-2w93 · Severity: medium · Ecosystem: go — etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic
In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are being read during consensus as an arbitrary etcd consensus participant could go down from a runtime panic when reading the entry.
Conclusion & alert: CVE-2020-15112 is rated Moderate Risk (50.1/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.26%). Core evidence: EPSS rose +1.14% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.12% | 1.26% | +1.14% |
| 2 | 2025-11-21 | 0.30% | 0.12% | -0.18% |
| 3 | 2025-11-18 | — | 0.30% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| 4.0 | 2.0 | MEDIUM |
|
8.0 | 2.9 | [email protected] |
GHSA-m332-53r6-2w93 · Severity: medium · Ecosystem: go — etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2020-15112 not yet assigned priority: Debian including 1 source packages (etcd), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2020-15112 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2020-15112 |
suse
|
medium | CVE-2020-15112 severity moderate: SUSE including 27 source package names (1.17.17:kubernetes-client-1.17.13-4.21.2, 1.17.17:kubernetes-common-1.17.13-4.21.2, …), 35 product×package rows across 13 product lines (Container caasp/v4/coredns, Container caasp/v4/etcd, … (13 product lines)): Fixed 35. | https://www.suse.com/security/cve/CVE-2020-15112/ |
ubuntu
|
medium | CVE-2020-15112 medium priority: Ubuntu including 1 source packages (etcd), 16 status rows across 16 suites (bionic, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): ignored 8, needed 4, released 3, DNE 1. | https://ubuntu.com/security/CVE-2020-15112 |