Information disclosure in etcd - CVE-2023-32082
Published: June 6, 2023
Vulnerability identifier: #VU76971
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32082
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the LeaseTimeToLive API. A remote user can gain unauthorized access to key names associated to a lease when "Keys" parameter is true.
Affected software
etcd
Red Hat OpenStack
openEuler
etcd
etcd (Red Hat package)
Red Hat OpenStack
openEuler
etcd
etcd (Red Hat package)
How to mitigate CVE-2023-32082
Install updates from vendor's website.
etcd - addressed in versions 3.4.26, 3.5.9
etcd - addressed in versions 3.4.14-8, 3.4.14-9, 3.4.14-11
etcd (Red Hat package) - update to 3.4.26-1.el9ost
etcd - addressed in versions 3.4.14-8, 3.4.14-9, 3.4.14-11
etcd (Red Hat package) - update to 3.4.26-1.el9ost