Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-24687

Опубликовано: 24 фев. 2022
Источник: debian

Описание

HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:write to register a specifically-defined service that can cause Consul servers to panic. Fixed in 1.9.15, 1.10.8, and 1.11.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
consulfixed1.9.17+dfsg2-1package
consulend-of-lifebullseyepackage
consulnot-affectedbusterpackage

Примечания

  • https://discuss.hashicorp.com/t/hcsec-2022-05-consul-ingress-gateway-panic-can-shutdown-servers/

  • https://github.com/hashicorp/consul/commit/d35c6a97cbdff252f5238d6b52f49786f896566a (v1.9.15)

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 4 года назад

HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:write to register a specifically-defined service that can cause Consul servers to panic. Fixed in 1.9.15, 1.10.8, and 1.11.3.

CVSS3: 6.5
nvd
почти 4 года назад

HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:write to register a specifically-defined service that can cause Consul servers to panic. Fixed in 1.9.15, 1.10.8, and 1.11.3.

CVSS3: 6.5
github
почти 4 года назад

HashiCorp Consul Ingress Gateway Panic Can Shutdown Servers