Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rqjq-ww83-wv5c

Опубликовано: 03 июн. 2023
Источник: github
Github: Прошло ревью
CVSS3: 8.7

Описание

Hashicorp Consul allows user with service:write permissions to patch remote proxy instances

Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.

Пакеты

Наименование

github.com/hashicorp/consul

go
Затронутые версииВерсия исправления

>= 1.15.0, < 1.15.3

1.15.3

EPSS

Процентиль: 45%
0.00585
Низкий

8.7 High

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 8.7
ubuntu
около 3 лет назад

Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.

CVSS3: 8.7
nvd
около 3 лет назад

Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.

CVSS3: 6.5
msrc
около 3 лет назад

Consul Envoy Extension Downsteam Proxy Configuration By Upstream Service Owner

CVSS3: 8.7
debian
около 3 лет назад

Consul and Consul Enterprise allowed any user with service:write permi ...

EPSS

Процентиль: 45%
0.00585
Низкий

8.7 High

CVSS3

Дефекты

CWE-266