CVE-2026-33343
etcd: Nested etcd transactions bypass RBAC authorization checks
描述
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, an authenticated user with RBAC restricted permissions on key ranges can use nested transactions to bypass all key-level authorization. This allows any authenticated user with direct access to etcd to effectively ignore all key range restrictions, accessing the entire etcd data store. Kubernetes does not rely on etcd’s built-in authentication and authorization. Instead, the API server handles authentication and authorization itself, so typical Kubernetes deployments are not affected. Versions 3.4.42, 3.5.28, and 3.6.9 contain a patch. If upgrading is not immediately possible, reduce exposure by treating the affected RPCs as unauthenticated in practice. Restrict network access to etcd server ports so only trusted components can connect and require strong client identity at the transport layer, such as mTLS with tightly scoped client certificate distribution.
如何修補 CVE-2026-33343
要修補 CVE-2026-33343,請將受影響套件升級到下列已修補版本。
- —升級至 3.4.42 或更新版本
- —未列出修補版本
- —未列出修補版本
- —未列出修補版本
- —升級至 3.6.9 或更新版本
- —升級至 3.4.42 或更新版本
CVE-2026-33343 正在被利用嗎?
低 — EPSS 為 0.2%,目前沒有觀察到大規模利用活動。
受影響套件(6)
- from 0, < 3.4.42, >= 3.5.0, < 3.5.28, >= 3.6.0, < 3.6.9
- from 0
- from 0, <= 3.3.27
- from 0
- >= 3.6.0-alpha.0, < 3.6.9
- from 0, < 3.4.42, >= 3.5.0-alpha.0, < 3.5.28, >= 3.6.0-alpha.0, < 3.6.9
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | NONE0.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N |