CVE-2023-32082Low· 3.1▾ Sunlitetcd Key name can be accessed via LeaseTimeToLive API
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
LeaseTimeToLive API allows access to key names (not value) associated to a lease when Keys parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC).
< v3.4.26 and < v3.5.9 are affected.
No.
Yoni Rozenshein
github.com/etcd-io/etcd < 3.4.26github.com/etcd-io/etcd >= 3.5.0, < 3.5.9Upgrade to a patched release:
github.com/etcd-io/etcd 3.4.26github.com/etcd-io/etcd 3.5.9