GHSA-9gp7-6833-wv89
Dashboard / Vulnerabilities / GHSA-9gp7-6833-wv89
GHSA-9gp7-6833-wv89
Summary: etcd having a negative value for cluster node size results in an index out-of-bound panic during service discovery
Details: ### Vulnerability type Data Validation ### Detail When an etcd instance attempts to perform service discovery, if a cluster size is provided as a negative value, the etcd instance will panic without recovery. ### References Find out more on this vulnerability in the [security audit report](https://github.com/etcd-io/etcd/blob/master/security/SECURITY_AUDIT.pdf) ### For more information If you have any questions or comments about this advisory: * Contact the [etcd security committee](https://github.com/etcd-io/etcd/blob/master/security/security-release-process.md#product-security-committee-psc)
References: https://github.com/etcd-io/etcd/security/advisories/GHSA-9gp7-6833-wv89, https://github.com/etcd-io/etcd
Affected packages
Package
Name: go.etcd.io/etcd/client/v3
Purl: pkg:golang/go.etcd.io/etcd/client/v3
Affected ranges
Type: SEMVER
Events:
