Description
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1459 | etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds. |
Github GHSA |
GHSA-3p4g-rcw5-8298 | etcd Key name can be accessed via LeaseTimeToLive API |
References
History
Fri, 24 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-24T21:29:23.721Z
Reserved: 2023-05-01T16:47:35.316Z
Link: CVE-2023-32082
Updated: 2024-08-02T15:03:29.172Z
Status : Modified
Published: 2023-05-11T20:15:09.500
Modified: 2024-11-21T08:02:40.597
Link: CVE-2023-32082
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA