Описание
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when Keys
parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds.
A flaw was found in etcd. Affected versions of etcd allow a remote, authenticated attacker to use the LeaseTimeToLive API to obtain sensitive information.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | etcd | Out of support scope | ||
Red Hat Enterprise Linux 7 | etcd3 | Out of support scope | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-etcd | Affected | ||
Red Hat OpenStack Platform 16.1 | etcd | Fix deferred | ||
Red Hat OpenStack Platform 16.2 | etcd | Fix deferred | ||
Red Hat Storage 3 | etcd | Affected | ||
Red Hat OpenStack Platform 17.0 | etcd | Fixed | RHSA-2023:3441 | 05.06.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.1 Low
CVSS3
Связанные уязвимости
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds.
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds.
etcd is a distributed key-value store for the data of a distributed sy ...
etcd Key name can be accessed via LeaseTimeToLive API
EPSS
3.1 Low
CVSS3