StackRadar

CVE-2020-15136

Medium

Advisory

Published 31 Jan 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.016
75th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
73
of 17,781 indexed, latest versions
Container images
61
deployed by those charts
Fix available
1 of 1
affected package

Etcd Gateway TLS authentication only applies to endpoints detected in DNS SRV records

Carried by container images the latest versions of 73 of 17,781 indexed charts deploy, on 61 images.

Affected packageAffected versionsFixed inImages
go.etcd.io/etcdgolangv0.0.0-20190215181705-784daa04988c, v0.0.0-20190228193606-a943ad0ee4c9, v0.0.0-20191023171146-3cf2f69b5738, v0.0.0-20200401174654-e694b7bb0875+12 more3.3.2361
OSV records
GHSA-wr2v-9rpq-c35q

Charts affected

73 by stars
ChartLatestAffected imagesRadar Score
kubefedmesosphere0.5.21 of 1See more

kubefed mesosphere 0.5.2

1 of the 1 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
mesosphere/kubefed:proxyurl4fd8889195fe
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.3.23

Open the chart page →

3,144
kube-oidc-proxymesosphere0.3.41 of 1See more

kube-oidc-proxy mesosphere 0.3.4

1 of the 1 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
go.etcd.io/etcd@v0.0.0-20191023171146-3cf2f69b5738
3.3.23

Open the chart page →

3,144
traefik2mesosphere9.18.01 of 1See more

traefik2 mesosphere 9.18.0

1 of the 1 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
library/traefik:2.4.8eda951fd29a8
go.etcd.io/etcd@v3.3.13+incompatible
3.3.23

Open the chart page →

3,341
kommandermesosphere-stable0.39.25 of 29See more

kommander mesosphere-stable 0.39.2

5 of the 29 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
mesosphere/kommander-federation-authorizedlister:v0.21.263bc411b930b
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.3.23
mesosphere/kommander-federation-controller-manager:v0.21.2b036785a8862
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.3.23
mesosphere/kommander-federation-webhook:v0.21.294af41b6dd9a
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.3.23
thanosio/thanos:v0.15.0b12d5c31bf5a
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200520232829-54ba9589114f
3.3.23
quay.io/kubernetes-multicluster/kubefed:v0.7.06d56f69b15a3
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
3.3.23

Open the chart page →

68,284
cortexmetakube0.6.01 of 2See more

cortex metakube 0.6.0

1 of the 2 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
quay.io/cortexproject/cortex:v1.9.05d1c2cf4c538
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200520232829-54ba9589114f
3.3.23

Open the chart page →

4,107
cert-manager-webhook-duckdnsmmontesVerified publisher1.2.31 of 1See more

cert-manager-webhook-duckdns mmontes 1.2.3

1 of the 1 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.3.23

Open the chart page →

2,847
corednsmoikot1.13.31 of 1See more

coredns moikot 1.13.3

1 of the 1 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
coredns/coredns:1.7.073ca82b4ce82
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200306183522-221f0cc107cb
3.3.23

Open the chart page →

2,547
opscruiseopenshift0.35.1002 of 11See more

opscruise openshift 0.35.100

2 of the 11 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
grafana/loki:2.0.077e138f81a8e
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200520232829-54ba9589114f
3.3.23
grafana/promtail:2.0.05fd12edcc694
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200520232829-54ba9589114f
3.3.23

Open the chart page →

8,201
scaleway-webhookparticuleio0.0.11 of 1See more

scaleway-webhook particuleio 0.0.1

1 of the 1 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.3.23

Open the chart page →

2,347
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
3.3.23

Open the chart page →

15,291
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
3.3.23

Open the chart page →

15,291
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.3.23

Open the chart page →

11,437
argocdromholdings1.8.11 of 3See more

argocd romholdings 1.8.1

1 of the 3 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
quay.io/dexidp/dex:v2.25.07bcf286807b8
go.etcd.io/etcd@v0.0.0-20191023171146-3cf2f69b5738
3.3.23

Open the chart page →

10,466
calicoromholdings0.1.13 of 4See more

calico romholdings 0.1.1

3 of the 4 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
go.etcd.io/etcd@v0.5.0-alpha.5.0.20201125193152-8a03d2e9614b
3.3.23
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
go.etcd.io/etcd@v0.5.0-alpha.5.0.20201125193152-8a03d2e9614b
3.3.23
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
go.etcd.io/etcd@v0.5.0-alpha.5.0.20201125193152-8a03d2e9614b
3.3.23

Open the chart page →

10,071
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
go.etcd.io/etcd@v0.0.0-20190228193606-a943ad0ee4c9
3.3.23

Open the chart page →

11,909
vaultstakaterVerified publisher0.8.41 of 2See more

vault stakater 0.8.4

1 of the 2 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200425165423-262c93980547
3.3.23

Open the chart page →

5,864
scaleway-webhooksudaVerified publisher0.0.21 of 1See more

scaleway-webhook suda 0.0.2

1 of the 1 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.3.23

Open the chart page →

2,347
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
go.etcd.io/etcd@v0.0.0-20200401174654-e694b7bb0875
3.3.23

Open the chart page →

2,869
vineyard-operatorvineyardVerified publisher0.24.21 of 2See more

vineyard-operator vineyard 0.24.2

1 of the 2 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
vineyardcloudnative/vineyard-operator:latest9d419aa18faa
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.3.23

Open the chart page →

4,525
cert-manager-webhook-vultrvultrVerified publisher1.0.01 of 1See more

cert-manager-webhook-vultr vultr 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
vultr/cert-manager-webhook-vultr:v0.1.0541c3e0aec58
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.3.23

Open the chart page →

2,500
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
gomods/athens:v0.11.0efb811df7844
go.etcd.io/etcd@v0.0.0-20190215181705-784daa04988c
3.3.23

Open the chart page →

4,984
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
go.etcd.io/etcd@v0.0.0-20201125193152-8a03d2e9614b
3.3.23

Open the chart page →

6,915
traefikwenerme9.1.11 of 1See more

traefik wenerme 9.1.1

1 of the 1 container images this version deploys carry CVE-2020-15136.

Container imageDigestPackageFixed in
library/traefik:2.2.8f5af5a5ce17f
go.etcd.io/etcd@v3.3.13+incompatible
3.3.23

Open the chart page →

3,369

Container images carrying it

61 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
vultr/cert-manager-webhook-vultr:v0.1.0541c3e0aec58
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.3.23
1
vultr/vultr-cloud-controller-manager:v0.3.01806f17d620c
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
3.3.23
1
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
3.3.23
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
go.etcd.io/etcd@v0.5.0-alpha.5.0.20210428180535-15715dcf1ace
3.3.23
1
quay.io/cortexproject/cortex:v1.9.05d1c2cf4c538
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200520232829-54ba9589114f
3.3.23
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
go.etcd.io/etcd@v0.0.0-20211004023027-19e2e70e4f50
3.3.23
1
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
go.etcd.io/etcd@v0.0.0-20191023171146-3cf2f69b5738
3.3.23
1
quay.io/kube-ops/loki:2.2.14fbd63194674
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200520232829-54ba9589114f
3.3.23
1
quay.io/kube-ops/promtail:2.2.134de6387233b
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200520232829-54ba9589114f
3.3.23
1
quay.io/kubernetes-multicluster/kubefed:v0.7.06d56f69b15a3
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
3.3.23
1
quay.io/openshift/origin-cli:4.66722d5041b47
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.3.23
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.