Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9gp7-6833-wv89

Опубликовано: 06 окт. 2022
Источник: github
Github: Прошло ревью

Описание

etcd having a negative value for cluster node size results in an index out-of-bound panic during service discovery

Vulnerability type

Data Validation

Detail

When an etcd instance attempts to perform service discovery, if a cluster size is provided as a negative value, the etcd instance will panic without recovery.

References

Find out more on this vulnerability in the security audit report

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

go.etcd.io/etcd/client/v3

go
Затронутые версииВерсия исправления

>= 3.4.0, < 3.4.10

3.4.10

Наименование

go.etcd.io/etcd/client/v3

go
Затронутые версииВерсия исправления

< 3.3.23

3.3.23