Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-chgm-7r52-whjj

Опубликовано: 31 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.6
CVSS3: 8.1

Описание

Hashicorp Consul Path Traversal vulnerability

A vulnerability was identified in Consul and Consul Enterprise ("Consul") such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules.

Пакеты

Наименование

github.com/hashicorp/consul

go
Затронутые версииВерсия исправления

>= 1.9.0, < 1.20.1

1.20.1

EPSS

Процентиль: 9%
0.00035
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.1
ubuntu
8 месяцев назад

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules.

CVSS3: 8.1
redhat
8 месяцев назад

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules.

CVSS3: 8.1
nvd
8 месяцев назад

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules.

CVSS3: 8.1
debian
8 месяцев назад

A vulnerability was identified in Consul and Consul Enterprise (\u201c ...

CVSS3: 8.1
fstec
8 месяцев назад

Уязвимость инструмента настройки сервиса Consul, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю обойти ограничения безопасности

EPSS

Процентиль: 9%
0.00035
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-22