Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

CVE-2023-32082 @ Go-go.etcd.io/etcd/server/v3-v3.5.0 #119

Closed
apcxtest opened this issue Aug 17, 2023 · 0 comments
Closed

CVE-2023-32082 @ Go-go.etcd.io/etcd/server/v3-v3.5.0 #119

apcxtest opened this issue Aug 17, 2023 · 0 comments

Comments

@apcxtest
Copy link
Owner

Vulnerable Package issue exists @ Go-go.etcd.io/etcd/server/v3-v3.5.0 in branch main

The package etcd is a distributed key-value store for the data of a distributed system. In versions prior to 3.4.26, 3.5.x prior to 3.5.9, and 3.6.0-alpha.0 the "LeaseTimeToLive" API allows access to key names (not value) associated with a lease when "Keys" parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster that enables auth (RBAC).

Namespace: apcxtest
Repository: test-repo-pub
Repository Url: https://github.com/apcxtest/test-repo-pub
CxAST-Project: apcxtest/test-repo-pub
CxAST platform scan: a314b9e1-0b75-4c05-86f0-fa4203a6e7fd
Branch: main
Application: test-repo-pub
Severity: MEDIUM
State: TO_VERIFY
Status: RECURRENT
CWE: CWE-200


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: LOW
Availability impact: NONE
Remediation Upgrade Recommendation: v3.5.9


References
Advisory
Pull request
Commit
Release Note
Pull request
Commit

# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

No branches or pull requests

1 participant