Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-10086

Опубликовано: 30 окт. 2024
Источник: redhat
CVSS3: 6.1

Описание

A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS.

A flaw was found in Consul and Consul Enterprise. This vulnerability allows reflected Cross-site scripting (XSS) attacks via missing Content-Type HTTP header in server responses, enabling misinterpretation of user-provided inputs.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Dev Spacesdevspaces/traefik-rhel8Will not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2322859consul: Consul Vulnerable To Reflected XSS On Content-Type Error Manipulation

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
8 месяцев назад

A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS.

CVSS3: 6.1
nvd
8 месяцев назад

A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS.

CVSS3: 6.1
debian
8 месяцев назад

A vulnerability was identified in Consul and Consul Enterprise such th ...

CVSS3: 6.1
github
8 месяцев назад

Hashicorp Consul Cross-site Scripting vulnerability

CVSS3: 6.1
fstec
8 месяцев назад

Уязвимость инструмента настройки сервиса Consul, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

6.1 Medium

CVSS3