Skip to content

A negative value for cluster node size results in an index out-of-bound panic during service discovery

Low
spzala published GHSA-9gp7-6833-wv89 Aug 5, 2020

Package

etcdserver

Affected versions

<= 3.4.9

Patched versions

3.4.10, 3.3.23

Description

Vulnerability type

Data Validation

Detail

When an etcd instance attempts to perform service discovery, if a cluster size is provided as a negative value, the etcd instance will panic without recovery.

References

Find out more on this vulnerability in the security audit report

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs