Back

MEDIUM

etcd key name can be accessed via LeaseTimeToLive API

Published May 11, 2023

Description

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds.

Affected products

Remediation

No remediation recorded yet.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 11, 2023
Updated Jan 24, 2025
Reserved May 1, 2023
CISA Vulnrichment
Updated Jan 24, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date May 11, 2023
ENISA EUVD
Assigner GitHub_M
Published May 11, 2023
Updated Jan 24, 2025
Exploited since n/a
EUVD-2023-1459 GHSA-3P4G-RCW5-8298