Data Validation
The parseCompactionRetention function in embed/etcd.go allows the retention variable value to be negative and causes the node to execute the history compaction in a loop, taking more CPU than usual and spamming logs.
Find out more on this vulnerability in the security audit report
If you have any questions or comments about this advisory: * Contact the etcd security committee
{ "nvd_published_at": null, "github_reviewed_at": "2024-02-03T00:03:07Z", "severity": "LOW", "cwe_ids": [], "github_reviewed": true }