RHSA-2023:3441: Important: Red Hat OpenStack Platform 17.0 (etcd) security update
A highly-available key value store for shared configurationSecurity Fix(es): Information discosure via debug function (CVE-2021-28235) Key name can be accessed via LeaseTimeToLive API (CVE-2023-32082) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What vulnerabilities are addressed in RHSA-2023:3441?
RHSA-2023:3441 addresses information disclosure via the debug function (CVE-2021-28235) and allows key name access via the LeaseTimeToLive API (CVE-2023-32082).
What is the severity of RHSA-2023:3441?
The severity of RHSA-2023:3441 is classified as important, indicating it poses a significant risk to affected systems.
How do I fix the vulnerabilities in RHSA-2023:3441?
To fix the vulnerabilities in RHSA-2023:3441, users should update to etcd version 3.4.26-1.el9 or later.
Which software packages are affected by RHSA-2023:3441?
The affected software packages in RHSA-2023:3441 include etcd, etcd-debuginfo, and etcd-debugsource up to version 3.4.26-1.el9.
Is there a recommended action for users of RHSA-2023:3441?
Users of RHSA-2023:3441 are recommended to apply the security updates to mitigate the identified vulnerabilities.