Source: etcd Version: 3.4.23-4 Severity: important Tags: security upstream Forwarded: https://github.com/etcd-io/etcd/pull/15656 X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org>
Hi, The following vulnerability was published for etcd. CVE-2023-32082[0]: | etcd is a distributed key-value store for the data of a distributed | system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API | allows access to key names (not value) associated to a lease when | `Keys` parameter is true, even a user doesn't have read permission to | the keys. The impact is limited to a cluster which enables auth | (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known | workarounds. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2023-32082 https://www.cve.org/CVERecord?id=CVE-2023-32082 [1] https://github.com/etcd-io/etcd/pull/15656 [2] https://github.com/etcd-io/etcd/security/advisories/GHSA-3p4g-rcw5-8298 Please adjust the affected versions in the BTS as needed. Regards, Salvatore