Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hj93-5fg3-3chr

Опубликовано: 25 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

HashiCorp Consul Ingress Gateway Panic Can Shutdown Servers

HashiCorp Consul and Consul Enterprise 1.8.0 through 1.9.14, 1.10.7, and 1.11.2 has Uncontrolled Resource Consumption. Clusters with at least one ingress gateway configured may allow a user with service:write permission to register a specifically-defined service that can cause the Consul server to panic and shutdown. Versions 1.9.15, 1.10.8, and 1.11.3 contain patches for the problem.

Пакеты

Наименование

github.com/hashicorp/consul

go
Затронутые версииВерсия исправления

>= 1.8.0, <= 1.9.14

1.9.15

Наименование

github.com/hashicorp/consul

go
Затронутые версииВерсия исправления

>= 1.10.0, <= 1.10.7

1.10.8

Наименование

github.com/hashicorp/consul

go
Затронутые версииВерсия исправления

>= 1.11.0, <= 1.11.2

1.11.3

EPSS

Процентиль: 70%
0.00638
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 4 года назад

HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:write to register a specifically-defined service that can cause Consul servers to panic. Fixed in 1.9.15, 1.10.8, and 1.11.3.

CVSS3: 6.5
nvd
почти 4 года назад

HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:write to register a specifically-defined service that can cause Consul servers to panic. Fixed in 1.9.15, 1.10.8, and 1.11.3.

CVSS3: 6.5
debian
почти 4 года назад

HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, a ...

EPSS

Процентиль: 70%
0.00638
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400