Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cpfq-66p2-336j

Опубликовано: 12 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

Consul is vulnerable to arbitrary file read when configured with Kubernetes authentication

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

Пакеты

Наименование

github.com/hashicorp/consul

go
Затронутые версииВерсия исправления

< 1.18.21

1.18.21

Наименование

github.com/hashicorp/consul

go
Затронутые версииВерсия исправления

>= 1.22.0-rc1, < 1.22.5

1.22.5

Наименование

github.com/hashicorp/consul

go
Затронутые версииВерсия исправления

>= 1.19.0, < 1.21.11

1.21.11

EPSS

Процентиль: 6%
0.00022
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 6.8
ubuntu
16 дней назад

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

CVSS3: 6.8
redhat
16 дней назад

A flaw was found in HashiCorp Consul. When configured with Kubernetes authentication, a highly privileged attacker can exploit this vulnerability to perform arbitrary file reads. This could lead to the disclosure of sensitive information from the system.

CVSS3: 6.8
nvd
16 дней назад

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

CVSS3: 6.8
debian
16 дней назад

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22. ...

EPSS

Процентиль: 6%
0.00022
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-59