CVE-2023-32082

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease whe ...

Continue Reading
CVE-2023-32303

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
Security Updates for Microsoft SQL Server (April 2023)

The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability: - A remote code execution vulnerability. An attacker ...

Continue Reading

CVSS3 - CRITICAL

Security Updates for Microsoft SQL Server ODBC Driver (April 2023)

The Microsoft SQL Server driver installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability: - A remote code execution vulnerability. An a ...

Continue Reading

CVSS3 - HIGH

Security Updates for Microsoft SQL Server (April 2023)

The Microsoft SQL Server installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability: - A remote code execution vulnerability. An attacker ...

Continue Reading

CVSS3 - CRITICAL

Security Updates for Microsoft SQL Server ODBC Driver (April 2023)

The Microsoft SQL Server driver installation on the remote host is missing a security update. It is, therefore, affected by the following vulnerability: - A remote code execution vulnerability. An a ...

Continue Reading

CVSS3 - HIGH

RHEL 9 : edk2 (RHSA-2023:2165)

The remote Redhat Enterprise Linux 9 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2023:2165 advisory. - Existing CommBuffer checks in SmmEntryP ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

etcd Key name can be accessed via LeaseTimeToLive API

### Impact LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn't have read permission to the keys. The impact is limited t ...

Continue Reading

Back to Main

Subscribe for the latest news: