4.3
CVSSv3

CVE-2023-32082

Published: 11/05/2023 Updated: 22/05/2023
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds.

Vulnerable Product Search on Vulmon Subscribe to Product

etcd etcd

Vendor Advisories

Synopsis Important: Red Hat OpenStack Platform 170 (etcd) security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for etcd is now available for Red Hat OpenStack Platform 170(Wallaby)Red Hat Product S ...
Debian Bug report logs - #1036295 etcd: CVE-2023-32082 Package: src:etcd; Maintainer for src:etcd is Debian Go Packaging Team <team+pkg-go@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 18 May 2023 19:45:01 UTC Severity: important Tags: security, upstream Found in version etcd/ ...
DescriptionThe MITRE CVE dictionary describes this issue as: etcd is a distributed key-value store for the data of a distributed system Prior to versions 3426 and 359, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys The imp ...