CVE-2023-32082

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-32082
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-32082.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-32082
Aliases
Downstream
Published
2023-05-11T19:22:56Z
Modified
2025-10-20T20:18:12.532356Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
etcd key name can be accessed via LeaseTimeToLive API
Details

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when Keys parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ]
}
References

Affected packages

Git / github.com/etcd-io/etcd

Affected ranges

Type
GIT
Repo
https://github.com/etcd-io/etcd
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/etcd-io/etcd
Events

Affected versions

Other

0

api/v3.*

api/v3.5.0
api/v3.5.1
api/v3.5.2
api/v3.5.3
api/v3.5.4
api/v3.5.5
api/v3.5.6
api/v3.5.7
api/v3.5.8

client/pkg/v3.*

client/pkg/v3.5.0
client/pkg/v3.5.1
client/pkg/v3.5.2
client/pkg/v3.5.3
client/pkg/v3.5.4
client/pkg/v3.5.5
client/pkg/v3.5.6
client/pkg/v3.5.7
client/pkg/v3.5.8

client/v2.*

client/v2.305.0
client/v2.305.1
client/v2.305.2
client/v2.305.3
client/v2.305.4
client/v2.305.5
client/v2.305.6
client/v2.305.7
client/v2.305.8

client/v3.*

client/v3.5.0
client/v3.5.1
client/v3.5.2
client/v3.5.3
client/v3.5.4
client/v3.5.5
client/v3.5.6
client/v3.5.7
client/v3.5.8

etcdctl/v3.*

etcdctl/v3.5.0
etcdctl/v3.5.1
etcdctl/v3.5.2
etcdctl/v3.5.3
etcdctl/v3.5.4
etcdctl/v3.5.5
etcdctl/v3.5.6
etcdctl/v3.5.7
etcdctl/v3.5.8

etcdutl/v3.*

etcdutl/v3.5.0
etcdutl/v3.5.1
etcdutl/v3.5.2
etcdutl/v3.5.3
etcdutl/v3.5.4
etcdutl/v3.5.5
etcdutl/v3.5.6
etcdutl/v3.5.7
etcdutl/v3.5.8

pkg/v3.*

pkg/v3.5.0
pkg/v3.5.1
pkg/v3.5.2
pkg/v3.5.3
pkg/v3.5.4
pkg/v3.5.5
pkg/v3.5.6
pkg/v3.5.7
pkg/v3.5.8

raft/v3.*

raft/v3.5.0
raft/v3.5.1
raft/v3.5.2
raft/v3.5.3
raft/v3.5.4
raft/v3.5.5
raft/v3.5.6
raft/v3.5.7
raft/v3.5.8

server/v3.*

server/v3.5.0
server/v3.5.1
server/v3.5.2
server/v3.5.3
server/v3.5.4
server/v3.5.5
server/v3.5.6
server/v3.5.7
server/v3.5.8

tests/v3.*

tests/v3.5.0
tests/v3.5.1
tests/v3.5.2
tests/v3.5.3
tests/v3.5.4
tests/v3.5.5
tests/v3.5.6
tests/v3.5.7
tests/v3.5.8

v0.*

v0.1.0
v0.1.1
v0.1.2
v0.2.0
v0.2.0-rc0
v0.2.0-rc1
v0.2.0-rc2
v0.2.0-rc3
v0.2.0-rc4
v0.3.0
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.5.0-alpha.0
v0.5.0-alpha.1
v0.5.0-alpha.2
v0.5.0-alpha.3
v0.5.0-alpha.4
v0.5.0-alpha.5

v2.*

v2.0.0
v2.0.0-rc.1
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.0-alpha.0
v2.1.0-alpha.1
v2.1.0-rc.0
v2.1.1
v2.2.0
v2.2.0-alpha.0
v2.2.0-alpha.1
v2.2.0-rc.0
v2.3.0
v2.3.0-alpha.0
v2.3.0-alpha.1

v3.*

v3.0.0-beta.0
v3.1.0-alpha.0
v3.1.0-alpha.1
v3.1.0-rc.0
v3.1.0-rc.1
v3.2.0+git
v3.2.0-rc.0
v3.2.0-rc.1
v3.2.0_plus_git
v3.2.10_plus_git
v3.3.0-rc.0
v3.3.9_plus_git
v3.4.0
v3.4.0-rc.0
v3.4.0-rc.1
v3.4.0-rc.2
v3.4.0-rc.3
v3.4.0-rc.4
v3.4.1
v3.4.10
v3.4.11
v3.4.12
v3.4.13
v3.4.14
v3.4.15
v3.4.16
v3.4.17
v3.4.18
v3.4.19
v3.4.2
v3.4.20
v3.4.21
v3.4.22
v3.4.23
v3.4.24
v3.4.25
v3.4.3
v3.4.4
v3.4.5
v3.4.6
v3.4.7
v3.4.8
v3.4.9
v3.5.0
v3.5.1
v3.5.2
v3.5.3
v3.5.4
v3.5.5
v3.5.6
v3.5.7
v3.5.8