Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-44283

Опубликовано: 14 мая 2026
Источник: debian
EPSS Низкий

Описание

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
etcdfixed3.5.16-11package
etcdno-dsatrixiepackage
etcdno-dsabookwormpackage
etcdno-dsabullseyepackage

Примечания

  • https://github.com/etcd-io/etcd/security/advisories/GHSA-x35m-3gp4-4fh5

  • https://github.com/etcd-io/etcd/pull/21677

  • https://github.com/etcd-io/etcd/pull/21680

  • Fixed by: https://github.com/etcd-io/etcd/commit/e8ce1ae41f18a938d0d8ad85dbc034c489e468db (v3.5.30)

  • Fixed by: https://github.com/etcd-io/etcd/commit/500c535adbb8a5a444bbff9fa34cc1c10addee71 (v3.5.30)

EPSS

Процентиль: 13%
0.00225
Низкий

Связанные уязвимости

ubuntu
3 месяца назад

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.

CVSS3: 5.4
redhat
3 месяца назад

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.

nvd
3 месяца назад

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.

CVSS3: 6.5
msrc
2 месяца назад

etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks

github
3 месяца назад

etcd RBAC bypass allows unauthorized data access via PrevKv/lease attachment in nested transaction Put requests

EPSS

Процентиль: 13%
0.00225
Низкий