Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2xhq-gv6c-p224

Опубликовано: 31 янв. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.7

Описание

Etcd Gateway can include itself as an endpoint resulting in resource exhaustion

Vulnerability type

Denial of Service

Detail

The etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.

References

Find out more on this vulnerability in the security audit report

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

go.etcd.io/etcd

go
Затронутые версииВерсия исправления

>= 3.4.0-rc.0, <= 3.4.9

3.4.10

Наименование

go.etcd.io/etcd

go
Затронутые версииВерсия исправления

< 3.3.23

3.3.23

EPSS

Процентиль: 61%
0.00413
Низкий

7.7 High

CVSS3

Дефекты

CWE-400
CWE-772

Связанные уязвимости

CVSS3: 7.7
ubuntu
больше 5 лет назад

In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.

CVSS3: 7.7
redhat
больше 5 лет назад

In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.

CVSS3: 7.7
nvd
больше 5 лет назад

In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.

CVSS3: 7.7
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 7.7
debian
больше 5 лет назад

In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simpl ...

EPSS

Процентиль: 61%
0.00413
Низкий

7.7 High

CVSS3

Дефекты

CWE-400
CWE-772