Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5c4w-8hhh-3c3h

Опубликовано: 31 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 8.3

Описание

Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability

A vulnerability was identified in Consul and Consul Enterprise ("Consul") such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.

Пакеты

Наименование

github.com/hashicorp/consul

go
Затронутые версииВерсия исправления

>= 1.9.0, < 1.20.1

1.20.1

EPSS

Процентиль: 5%
0.00025
Низкий

6.9 Medium

CVSS4

8.3 High

CVSS3

Дефекты

CWE-116
CWE-644

Связанные уязвимости

CVSS3: 8.3
ubuntu
8 месяцев назад

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.

CVSS3: 8.3
redhat
8 месяцев назад

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.

CVSS3: 8.3
nvd
8 месяцев назад

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.

CVSS3: 8.3
debian
8 месяцев назад

A vulnerability was identified in Consul and Consul Enterprise (\u201c ...

CVSS3: 5.8
redos
7 месяцев назад

Уязвимость consul

EPSS

Процентиль: 5%
0.00025
Низкий

6.9 Medium

CVSS4

8.3 High

CVSS3

Дефекты

CWE-116
CWE-644