Data Validation
The parseCompactionRetention function in embed/etcd.go allows the retention variable value to be negative and causes the node to execute the history compaction in a loop, taking more CPU than usual and spamming logs.
Find out more on this vulnerability in the security audit report
If you have any questions or comments about this advisory: * Contact the etcd security committee
{
"github_reviewed": true,
"cwe_ids": [],
"github_reviewed_at": "2024-02-03T00:03:07Z",
"nvd_published_at": null,
"severity": "LOW"
}