Логотип exploitDog
bind: "CVE-2023-32082"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2023-32082"

Количество 7

Количество 7

ubuntu логотип

CVE-2023-32082

около 2 лет назад

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds.

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2023-32082

около 2 лет назад

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2023-32082

около 2 лет назад

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2023-32082

около 2 лет назад

etcd is a distributed key-value store for the data of a distributed sy ...

CVSS3: 3.1
EPSS: Низкий
redos логотип

ROS-20250203-02

5 месяцев назад

Уязвимость etcd

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3p4g-rcw5-8298

около 2 лет назад

etcd Key name can be accessed via LeaseTimeToLive API

CVSS3: 3.1
EPSS: Низкий
fstec логотип

BDU:2025-01413

около 2 лет назад

Уязвимость хранилища параметров конфигурации Etcd, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-32082

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds.

CVSS3: 3.1
0%
Низкий
около 2 лет назад
redhat логотип
CVE-2023-32082

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds.

CVSS3: 3.1
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-32082

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds.

CVSS3: 3.1
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-32082

etcd is a distributed key-value store for the data of a distributed sy ...

CVSS3: 3.1
0%
Низкий
около 2 лет назад
redos логотип
ROS-20250203-02

Уязвимость etcd

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-3p4g-rcw5-8298

etcd Key name can be accessed via LeaseTimeToLive API

CVSS3: 3.1
0%
Низкий
около 2 лет назад
fstec логотип
BDU:2025-01413

Уязвимость хранилища параметров конфигурации Etcd, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.3
0%
Низкий
около 2 лет назад

Уязвимостей на страницу