Описание
etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.
A flaw was found in etcd, a distributed key-value store. An authenticated user, without sufficient read or lease-related permissions, could bypass Role-Based Access Control (RBAC) authorization checks. This bypass occurs during transaction operations involving PrevKv or lease attachment in Put requests, potentially leading to unauthorized data access or lease attachment.
Отчет
This flaw in etcd allows an authenticated user without sufficient read or lease-related permissions to bypass RBAC authorization checks when invoking transaction operations that include PrevKv or lease attachment in Put requests. This can lead to unauthorized data disclosure or lease attachment. The flaw is exploitable only when etcd's built-in authentication and RBAC are enabled and an attacker has valid etcd client credentials with direct access to the etcd gRPC API. Typical Red Hat OpenShift Container Platform deployments are not affected under default configuration, as the Kubernetes API server handles authentication and authorization independently of etcd's internal mechanisms.
Меры по смягчению последствий
For OpenShift Container Platform until an update can be applied, reduce exposure by restricting network access to etcd server ports so only trusted control-plane components can connect and require strong client identity at the transport layer, such as mTLS with tightly scoped client certificate distribution; these measures limit direct access to the etcd data store but do not replace applying the security update.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift4/ose-etcd-rhel9 | Affected | ||
| Red Hat OpenStack Platform 16.2 | etcd | Under investigation | ||
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-etcd | Affected | ||
| Red Hat OpenStack Platform 17.1 | etcd | Under investigation | ||
| Red Hat OpenStack Platform 17.1 | rhosp-rhel9/openstack-etcd | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.4 Medium
CVSS3
Связанные уязвимости
etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.
etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.
etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks
etcd is a distributed key-value store for the data of a distributed sy ...
etcd RBAC bypass allows unauthorized data access via PrevKv/lease attachment in nested transaction Put requests
EPSS
5.4 Medium
CVSS3