Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cpfq-66p2-336j

Опубликовано: 12 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

Consul is vulnerable to arbitrary file read when configured with Kubernetes authentication

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

Пакеты

Наименование

github.com/hashicorp/consul

go
Затронутые версииВерсия исправления

< 1.18.21

1.18.21

Наименование

github.com/hashicorp/consul

go
Затронутые версииВерсия исправления

>= 1.22.0-rc1, < 1.22.5

1.22.5

Наименование

github.com/hashicorp/consul

go
Затронутые версииВерсия исправления

>= 1.19.0, < 1.21.11

1.21.11

EPSS

Процентиль: 39%
0.00475
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 6.8
ubuntu
5 месяцев назад

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

CVSS3: 6.8
redhat
5 месяцев назад

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

CVSS3: 6.8
nvd
5 месяцев назад

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

CVSS3: 6.8
debian
5 месяцев назад

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22. ...

CVSS3: 6.8
fstec
5 месяцев назад

Уязвимость инструмента настройки сервисов HashiCorp Consul Community Edition и Consul Enterprise, связанная с некорректным определением ссылки перед доступом к файлу, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 39%
0.00475
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-59