Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-10006

Опубликовано: 30 окт. 2024
Источник: ubuntu
Приоритет: medium
CVSS3: 8.3

Описание

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

noble

DNE

oracular

DNE

plucky

DNE

questing

DNE

Показывать по

Ссылки на источники

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
redhat
больше 1 года назад

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.

CVSS3: 8.3
nvd
больше 1 года назад

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.

CVSS3: 8.3
debian
больше 1 года назад

A vulnerability was identified in Consul and Consul Enterprise (\u201c ...

CVSS3: 8.3
github
больше 1 года назад

Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability

CVSS3: 5.8
fstec
больше 1 года назад

Уязвимость инструмента настройки сервисов Consul Community Edition и Consul Enterprise, связанная с непринятием мер по нейтрализации заголовков HTTP для синтаксиса сценариев, позволяющая нарушителю получить достпу к конфиденциальной информации

8.3 High

CVSS3