4.3 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
0.001 Low
EPSS
Percentile
39.4%
etcd is a distributed key-value store for the data of a distributed system.
Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access
to key names (not value) associated to a lease when Keys
parameter is
true, even a user doesn’t have read permission to the keys. The impact is
limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9
fix this issue. There are no known workarounds.
github.com/etcd-io/etcd/blob/main/CHANGELOG/CHANGELOG-3.4.md
github.com/etcd-io/etcd/blob/main/CHANGELOG/CHANGELOG-3.5.md
github.com/etcd-io/etcd/pull/15656
github.com/etcd-io/etcd/security/advisories/GHSA-3p4g-rcw5-8298
launchpad.net/bugs/cve/CVE-2023-32082
nvd.nist.gov/vuln/detail/CVE-2023-32082
security-tracker.debian.org/tracker/CVE-2023-32082
www.cve.org/CVERecord?id=CVE-2023-32082