CVE-2023-32082

LOW3.1EPSS 0.36%

etcd Key name can be accessed via LeaseTimeToLive API

Published: 5/12/2023Modified: 2/4/2026
Also known as:GHSA-3p4g-rcw5-8298BIT-etcd-2023-32082CGA-36vx-6qh6-4pw6

Description

### Impact LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). ### Patches < v3.4.26 and < v3.5.9 are affected. ### Workarounds No. ### Reporter Yoni Rozenshein

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1LOW3.1CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

References (7)