Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rqjq-ww83-wv5c

Опубликовано: 03 июн. 2023
Источник: github
Github: Прошло ревью
CVSS3: 8.7

Описание

Hashicorp Consul allows user with service:write permissions to patch remote proxy instances

Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.

Пакеты

Наименование

github.com/hashicorp/consul

go
Затронутые версииВерсия исправления

>= 1.15.0, < 1.15.3

1.15.3

EPSS

Процентиль: 37%
0.00156
Низкий

8.7 High

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 8.7
ubuntu
больше 2 лет назад

Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.

CVSS3: 8.7
nvd
больше 2 лет назад

Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.

CVSS3: 6.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 8.7
debian
больше 2 лет назад

Consul and Consul Enterprise allowed any user with service:write permi ...

EPSS

Процентиль: 37%
0.00156
Низкий

8.7 High

CVSS3

Дефекты

CWE-266