GHSA-9gp7-6833-wv89

Suggest an improvement
Source
https://github.com/advisories/GHSA-9gp7-6833-wv89
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/10/GHSA-9gp7-6833-wv89/GHSA-9gp7-6833-wv89.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-9gp7-6833-wv89
Published
2022-10-06T23:18:35Z
Modified
2022-10-06T23:18:35Z
Summary
etcd having a negative value for cluster node size results in an index out-of-bound panic during service discovery
Details

Vulnerability type

Data Validation

Detail

When an etcd instance attempts to perform service discovery, if a cluster size is provided as a negative value, the etcd instance will panic without recovery.

References

Find out more on this vulnerability in the security audit report

For more information

If you have any questions or comments about this advisory: * Contact the etcd security committee

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2022-10-06T23:18:35Z"
}
References

Affected packages

Go / go.etcd.io/etcd/client/v3

Package

Name
go.etcd.io/etcd/client/v3
View open source insights on deps.dev
Purl
pkg:golang/go.etcd.io/etcd/client/v3

Affected ranges

Type
SEMVER
Events
Introduced
3.4.0
Fixed
3.4.10

Go / go.etcd.io/etcd/client/v3

Package

Name
go.etcd.io/etcd/client/v3
View open source insights on deps.dev
Purl
pkg:golang/go.etcd.io/etcd/client/v3

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.3.23