Overview
About vulnerability
etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requests within transaction operations, to bypass RBAC authorization checks. An authenticated user without sufficient read or lease-related permissions may be able to access unauthorized data or attach leases by invoking transaction operations with these features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and 3.6.11.Details
- Affected product:
- FZambia/eagle , Grafana , Loki , apache/cassandra-gocql-driver/gocql , census-ecosystem/opencensus-go-exporter-prometheus/prometheus , centrifugal/centrifuge , coredns/coredns , cortexproject/cortex , etcd-io/etcd , etcd-io/etcd/client , etcd-io/etcd/server , go-kit/kit , golang-migrate/migrate , grafana/grafana-aws-sdk , grafana/grafana-live-sdk , grafana/grafana-plugin-sdk-go , grpc-ecosystem/go-grpc-middleware/providers/kit , hashicorp/consul , hashicorp/go-metrics , influxdata/flux , influxdata/influxdb , influxdata/promql , influxdata/telegraf , jaegertracing/jaeger , leoluk/perflib_exporter , open-telemetry/opentelemetry-collector , prometheus/alertmanager , prometheus/client_golang , prometheus/common , prometheus/exporter-toolkit , prometheus/node_exporter , prometheus/prometheus , prometheus/statsd_exporter , thanos-io/thanos , weaveworks/common
- Affected packages:
- go.etcd.io/etcd @ 0.5.0-alpha.5.0.20200520232829-54ba9589114f (+42 more)