Описание
HashiCorp Consul 0.5.1 through 1.4.0 can use cleartext agent-to-agent RPC communication because the verify_outgoing setting is improperly documented. NOTE: the vendor has provided reconfiguration steps that do not require a software upgrade.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needed |
| devel | DNE | |
| esm-apps/bionic | needed | |
| esm-apps/focal | not-affected | 1.5.2+dfsg2-14 |
| esm-apps/jammy | not-affected | |
| esm-infra-legacy/trusty | DNE | |
| focal | not-affected | 1.5.2+dfsg2-14 |
| groovy | not-affected | |
| hirsute | not-affected | |
| impish | not-affected |
Показывать по
EPSS
4.3 Medium
CVSS2
5.9 Medium
CVSS3
Связанные уязвимости
HashiCorp Consul 0.5.1 through 1.4.0 can use cleartext agent-to-agent RPC communication because the verify_outgoing setting is improperly documented. NOTE: the vendor has provided reconfiguration steps that do not require a software upgrade.
HashiCorp Consul 0.5.1 through 1.4.0 can use cleartext agent-to-agent ...
HashiCorp Consul can use cleartext agent-to-agent RPC communication
EPSS
4.3 Medium
CVSS2
5.9 Medium
CVSS3