Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS05Z3A3LTY4MzMtd3Y4Oc4AAvLw

etcd having a negative value for cluster node size results in an index out-of-bound panic during service discovery

Vulnerability type

Data Validation

Detail

When an etcd instance attempts to perform service discovery, if a cluster size is provided as a negative value, the etcd instance will panic without recovery.

References

Find out more on this vulnerability in the security audit report

For more information

If you have any questions or comments about this advisory:

Permalink: https://github.com/advisories/GHSA-9gp7-6833-wv89
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05Z3A3LTY4MzMtd3Y4Oc4AAvLw
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: over 1 year ago
Updated: over 1 year ago


Identifiers: GHSA-9gp7-6833-wv89
References: Repository: https://github.com/etcd-io/etcd
Blast Radius: 0.0

Affected Packages

go:go.etcd.io/etcd/client/v3
Dependent packages: 5,154
Dependent repositories: 20,636
Downloads:
Affected Version Ranges: < 3.3.23, >= 3.4.0, < 3.4.10
Fixed in: 3.3.23, 3.4.10
All affected versions:
All unaffected versions: 3.5.0, 3.5.1, 3.5.2, 3.5.3, 3.5.4, 3.5.5, 3.5.6, 3.5.7, 3.5.8, 3.5.9, 3.5.10, 3.5.11, 3.5.12, 3.5.13