Etcd Unauthenticated Access - Members List
etcd-unauth is a high severity check in the
devops category, written in yaml.
Its source is templates/devops/etcd/new-etcd-vulnerable-unauthenticated.yaml in
cert-x-gen-templates.
What it checks
Section titled “What it checks”Detects unauthenticated access to etcd on port 2379 by attempting to list cluster members via the HTTP API.
Header
Section titled “Header”| Field | Value |
|---|---|
| Id | etcd-unauth |
| Severity | high |
| Language | yaml |
| Category | devops |
| Author | CERT-X-GEN |
| Template version | not recorded |
| Confidence | not recorded |
| CVSS | not recorded |
| Weakness | not recorded |
| Tags | etcd, unauthenticated, database, key-value |
| Target kind | not recorded |
| Oracle | not recorded |
The file declares http as well. Those are not tabled above; read the
source for what they carry.
Run it
Section titled “Run it”To see what the copy on your machine says about itself, and to confirm it is installed at all:
cxg template info etcd-unauthThe id it prints is the one to pass anywhere a template is selected. See
cxg template for the rest of
the subcommand, Scan a target for running
a scan, and
A match is not a finding for how
to read what comes back.
Related
Section titled “Related”- Template catalog is the whole corpus.
- devops is the rest of this category.
- Contribute a template is the route from a check you needed and could not find to a merged one.

