ConsulGHSA-gw2g-hhc9-wgjh
Missing Authorization in HashiCorp Consul
High7.5CVE-2022-3920 · Published Nov 16, 2022 · updated Aug 7, 2026
HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/consul Go | >= 1.13.0, < 1.14.0 | 1.14.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-862
- Also known as
- BIT-consul-2022-3920, CVE-2022-3920, GO-2022-1121
More Consul advisories
All Consul| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 92023 | Consul Server Panic when Ingress and API Gateways Configured with Peering Connections | Medium6.5 | 1.14.5 |
| Sep 252022 | HashiCorp Consul vulnerable to authorization bypass | Medium6.5 | 1.11.9+2 more |
| Sep 252022 | HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions | High7.1 | 1.11.9+2 more |
| May 242022 | HashiCorp Consul Cross-site Scripting vulnerability | Medium6.1 | 1.7.14+2 more |
| May 142022 | HashiCorp Consul can use cleartext agent-to-agent RPC communication | Medium5.9 | 1.4.1 |
| May 132022 | HashiCorp Consul vulnerable to Origin Validation Error | High7.4 | 1.4.4 |