Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2023-32082

etcd: LeaseTimeToLive exposes key names without read permission

Technology

etcd

CVSS Score

4.3 / 10.0

Affected Versions

etcd before 3.4.26, 3.5.0 to 3.5.8

Upstream Fix

3.4.26, 3.5.9

Published

May 11, 2023

OSSeva Coverage

Fixed upstream

Description

With the Keys parameter set, the LeaseTimeToLive API returns the names, but not the values, of keys attached to a lease even when the user has no read permission on them. Only clusters with authentication enabled are affected.

Upstream record: NVD · CVE.org

Is your etcd deployment affected?

If you're running etcd before 3.4.26, 3.5.0 to 3.5.8, you need this patch. Book a discovery call to get covered.