| id: GO-2024-2528 |
| modules: |
| - module: go.etcd.io/etcd |
| vulnerable_at: 2.3.8+incompatible |
| - module: go.etcd.io/etcd/v3 |
| non_go_versions: |
| - fixed: 3.3.23 |
| - introduced: 3.4.0-rc.0 |
| - fixed: 3.4.10 |
| vulnerable_at: 3.5.14 |
| summary: Etcd Gateway TLS endpoint validation only confirms TCP reachability in go.etcd.io/etcd |
| ghsas: |
| - GHSA-j86v-2vjr-fg8f |
| references: |
| - advisory: https://github.com/etcd-io/etcd/security/advisories/GHSA-j86v-2vjr-fg8f |
| source: |
| id: GHSA-j86v-2vjr-fg8f |
| created: 2024-06-26T16:10:23.766937-04:00 |
| review_status: UNREVIEWED |
| unexcluded: EFFECTIVELY_PRIVATE |