ConsulGHSA-496g-fr33-whrf
Denial of service in HashiCorp Consul
High7.5CVE-2020-25201 · Published Jan 31, 2024 · updated Jun 28, 2024
HashiCorp Consul Enterprise versions 1.7.0 up to 1.7.8 and 1.8.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7.9 and 1.8.5.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/consul Go | >= 1.7.0, < 1.7.9 | 1.7.9 |
| >= 1.8.0, < 1.8.5 | 1.8.5 |
Details and references
More Consul advisories
All Consul| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 312024 | Hashicorp Consul Path Traversal vulnerability | High8.1 | 1.20.1 |
| Jan 312024 | Privilege Escalation in HashiCorp Consul | Medium6.5 | 1.6.10+2 more |
| Aug 92023 | Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers | High7.4 | 1.16.1 |
| Jun 92023 | HashiCorp Consul Incorrect Access Control vulnerability | High7.5 | 1.5.1 |
| Jun 32023 | Hashicorp Consul vulnerable to denial of service | Medium4.9 | 1.14.5+1 more |
| Jun 32023 | Hashicorp Consul allows user with service:write permissions to patch remote proxy instances | High8.7 | 1.15.3 |