-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| go.etcd.io/etcd/v3 | go | >= 3.4.0-rc.0, <= 3.4.9 | 3.4.10 |
| go.etcd.io/etcd/v3 | go | < 3.3.23 | 3.3.23 |
The vulnerability description explicitly identifies parseCompactionRetention in embed/etcd.go as the source of improper input validation. The function's failure to reject negative retention values directly causes the compaction loop described. Multiple sources (security audit report, GitHub advisory) confirm this root cause without requiring commit diffs. No other functions are mentioned in the vulnerability details.
Ongoing coverage of React2Shell