LOW3.1
GHSA-3p4g-rcw5-8298
etcd Key name can be accessed via LeaseTimeToLive API
Quick fix
GHSA-3p4g-rcw5-8298 — github.com/etcd-io/etcd: upgrade to the fixed version with the command below.
go get github.com/etcd-io/etcd@v3.4.26Details
### Impact LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC).
### Patches < v3.4.26 and < v3.5.9 are affected.
### Workarounds No.
### Reporter Yoni Rozenshein
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/etcd-io/etcd
Introduced in:
3.5.0Fixed in: 3.5.9Fix
go get github.com/etcd-io/etcd@v3.5.9References
- https://github.com/etcd-io/etcd/security/advisories/GHSA-3p4g-rcw5-8298[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-32082[ADVISORY]
- https://github.com/etcd-io/etcd/pull/15656[WEB]
- https://github.com/etcd-io/etcd[PACKAGE]
- https://github.com/etcd-io/etcd/blob/main/CHANGELOG/CHANGELOG-3.4.md[WEB]
- https://github.com/etcd-io/etcd/blob/main/CHANGELOG/CHANGELOG-3.5.md[WEB]