Описание
HashiCorp Consul Enterprise version 1.8.0 up to 1.9.4 audit log can be bypassed by specifically crafted HTTP events. Fixed in 1.9.5, and 1.8.10.
A flaw was found in the hashicorp consul, where the audit log could be bypassed. The highest threat from this vulnerability is to integrity.
Отчет
This vulnerability only affects the enterprise version of consul, which includes audit-logging [1]. Hence OpenShift Container Platform (OCP), OpenShift ServiceMesh (OSSM), and OpenShift Virtualization are not affected. [1] - https://www.consul.io/docs/enterprise/audit-logging
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Service Mesh 2.0 | servicemesh | Not affected | ||
| OpenShift Service Mesh 2.0 | servicemesh-prometheus | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/metrics-collector-rhel9 | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/multicluster-observability-rhel8-operator | Not affected | ||
| Red Hat Fuse 7 | consul-client | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/cnf-tests-rhel8 | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/compliance-rhel8-operator | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/file-integrity-rhel8-operator | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-baremetal-machine-controllers | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-etcd-rhel8-operator | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
HashiCorp Consul Enterprise version 1.8.0 up to 1.9.4 audit log can be bypassed by specifically crafted HTTP events. Fixed in 1.9.5, and 1.8.10.
HashiCorp Consul Enterprise version 1.8.0 up to 1.9.4 audit log can be bypassed by specifically crafted HTTP events. Fixed in 1.9.5, and 1.8.10.
HashiCorp Consul Enterprise version 1.8.0 up to 1.9.4 audit log can be ...
HashiCorp Consul Enterprise version 1.8.0 up to 1.9.4 audit log can be bypassed by specifically crafted HTTP events. Fixed in 1.9.5, and 1.8.10.
EPSS
7.5 High
CVSS3