GHSA-5x4g-q5rc-36jp: Etcd pkg Insecure ciphers are allowed by default
(updated )
Vulnerability type
Cryptography
Detail
The TLS ciphers list supported by etcd contains insecure cipher suites. Users can configure the desired ciphers using the “–cipher-suites” flag, and a default list of secure cipher suites is used if empty.
Workarounds
By default, no action is required. If users want to specify cipher suites using the ‘–cipher-suites’ flag, they should try not to specify insecure cipher suites. Please refer to the security documentation.
References
Find out more on this vulnerability in the security audit report
References
Code Behaviors & Features
Detect and mitigate GHSA-5x4g-q5rc-36jp with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →