etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds. https://github.com/etcd-io/etcd/security/advisories/GHSA-3p4g-rcw5-8298 https://github.com/etcd-io/etcd/blob/main/CHANGELOG/CHANGELOG-3.5.md https://github.com/etcd-io/etcd/pull/15656 https://github.com/etcd-io/etcd/blob/main/CHANGELOG/CHANGELOG-3.4.md
Created etcd tracking bugs for this issue: Affects: fedora-all [bug 2208132] Affects: openstack-rdo [bug 2208133]
This issue has been addressed in the following products: Red Hat OpenStack Platform 17.0 Via RHSA-2023:3441 https://access.redhat.com/errata/RHSA-2023:3441
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2023-32082