Headline
GHSA-9gp7-6833-wv89: etcd having a negative value for cluster node size results in an index out-of-bound panic during service discovery
Vulnerability type
Data Validation
Detail
When an etcd instance attempts to perform service discovery, if a cluster size is provided as a negative value, the etcd instance will panic without recovery.
References
Find out more on this vulnerability in the security audit report
For more information
If you have any questions or comments about this advisory:
- Contact the etcd security committee
- GitHub Advisory Database
- GitHub Reviewed
- GHSA-9gp7-6833-wv89
etcd having a negative value for cluster node size results in an index out-of-bound panic during service discovery
Low severity GitHub Reviewed Published Oct 6, 2022 in etcd-io/etcd • Updated Oct 6, 2022
Package
gomod go.etcd.io/etcd/client/v3 (Go)
Affected versions
>= 3.4.0, < 3.4.10
< 3.3.23
Patched versions
3.4.10
3.3.23
Description
Vulnerability type
Data Validation
Detail
When an etcd instance attempts to perform service discovery, if a cluster size is provided as a negative value, the etcd instance will panic without recovery.
References
Find out more on this vulnerability in the security audit report
For more information
If you have any questions or comments about this advisory:
- Contact the etcd security committee
References
- GHSA-9gp7-6833-wv89
GHSA ID
GHSA-9gp7-6833-wv89
Source code