Site icon API Security Blog

etcd Key name can be accessed via LeaseTimeToLive API

### Impact
LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn’t have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC).

### Patches
Read More

Exit mobile version