consulGHSA-chgm-7r52-whjj
Hashicorp Consul Path Traversal vulnerability
High8.1CVE-2024-10005 · Published Oct 31, 2024 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/consul Go | >= 1.9.0, < 1.20.1 | 1.20.1 |
Details and references
A vulnerability was identified in Consul and Consul Enterprise ("Consul") such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- BIT-consul-2024-10005, CVE-2024-10005, GO-2024-3243
- nvd.nist.gov/vuln/detail/CVE-2024-10005
- github.com/hashicorp/consul/pull/21816
- github.com/hashicorp/consul/commit/d9206fc7e284a9244af4d62f8653a63ca30bd00c
- discuss.hashicorp.com/t/hcsec-2024-22-consul-l7-intentions-vulnerable-to-url-path-bypass
- github.com/advisories/GHSA-chgm-7r52-whjj
- github.com/hashicorp/consul
- security.netapp.com/advisory/ntap-20250110-0004
More consul advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 312024 | Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability CVE-2024-10006Medium8.3fixed in 1.20.1 | Medium8.3 | 1.20.1 |
| Oct 312024 | Hashicorp Consul Cross-site Scripting vulnerability CVE-2024-10086Medium6.1fixed in 1.20.0 | Medium6.1 | 1.20.0 |
| Jan 312024 | Privilege Escalation in HashiCorp Consul CVE-2020-28053Medium6.5fixed in 1.6.10, 1.7.10, 1.8.6 | Medium6.5 | 1.6.10, 1.7.10, 1.8.6 |
| Jan 312024 | Denial of service in HashiCorp Consul CVE-2020-25201High7.5fixed in 1.7.9, 1.8.5 | High7.5 | 1.7.9, 1.8.5 |
| Oct 282025 | Consul key/value endpoint is vulnerable to denial of service CVE-2025-11374Medium6.5fixed in 1.22.0 | Medium6.5 | 1.22.0 |
| Oct 282025 | Consul event endpoint is vulnerable to denial of service CVE-2025-11375Medium6.5fixed in 1.22.0 | Medium6.5 | 1.22.0 |