Skip to content

Key name can be accessed via LeaseTimeToLive API

Low
mitake published GHSA-3p4g-rcw5-8298 May 11, 2023

Package

No package listed

Affected versions

< v3.4.26 and < v3.5.9

Patched versions

v3.4.26 and v3.5.9

Description

Impact

LeaseTimeToLive API allows access to key names (not value) associated to a lease when Keys parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC).

Patches

< v3.4.26 and < v3.5.9 are affected.

Workarounds

No.

Reporter

Yoni Rozenshein

Severity

Low

CVE ID

CVE-2023-32082

Weaknesses

No CWEs