Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS05Z3A3LTY4MzMtd3Y4Oc4AAvLw
etcd having a negative value for cluster node size results in an index out-of-bound panic during service discovery
Vulnerability type
Data Validation
Detail
When an etcd instance attempts to perform service discovery, if a cluster size is provided as a negative value, the etcd instance will panic without recovery.
References
Find out more on this vulnerability in the security audit report
For more information
If you have any questions or comments about this advisory:
- Contact the etcd security committee
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05Z3A3LTY4MzMtd3Y4Oc4AAvLw
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: about 2 years ago
Updated: almost 2 years ago
Identifiers: GHSA-9gp7-6833-wv89
References:
- https://github.com/etcd-io/etcd/security/advisories/GHSA-9gp7-6833-wv89
- https://github.com/advisories/GHSA-9gp7-6833-wv89
Blast Radius: 0.0
Affected Packages
go:go.etcd.io/etcd/client/v3
Dependent packages: 5,154Dependent repositories: 20,636
Downloads:
Affected Version Ranges: < 3.3.23, >= 3.4.0, < 3.4.10
Fixed in: 3.3.23, 3.4.10
All affected versions:
All unaffected versions: 3.5.0, 3.5.1, 3.5.2, 3.5.3, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.5.8, 3.5.9, 3.5.10, 3.5.11, 3.5.12, 3.5.13, 3.5.14, 3.5.15, 3.5.16, 3.5.17