Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q7fx-wm2p-qfj8

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.4

Описание

HashiCorp Consul vulnerable to Origin Validation Error

HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if verify_server_hostname were set to false, even when it is actually set to true. This is fixed in 1.4.4.

Пакеты

Наименование

github.com/hashicorp/consul

go
Затронутые версииВерсия исправления

< 1.4.4

1.4.4

EPSS

Процентиль: 40%
0.00183
Низкий

7.4 High

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 7.4
ubuntu
почти 7 лет назад

HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if verify_server_hostname were set to false, even when it is actually set to true. This is fixed in 1.4.4.

CVSS3: 7.4
nvd
почти 7 лет назад

HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if verify_server_hostname were set to false, even when it is actually set to true. This is fixed in 1.4.4.

CVSS3: 7.4
debian
почти 7 лет назад

HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to ...

EPSS

Процентиль: 40%
0.00183
Низкий

7.4 High

CVSS3

Дефекты

CWE-346