Skip to content
ConsulGHSA-gw2g-hhc9-wgjh

Missing Authorization in HashiCorp Consul

High7.5CVE-2022-3920 · Published Nov 16, 2022 · updated Aug 7, 2026

HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
>= 1.13.0, < 1.14.01.14.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-862
Also known as
BIT-consul-2022-3920, CVE-2022-3920, GO-2022-1121

More Consul advisories

All Consul
Advisory
Consul Server Panic when Ingress and API Gateways Configured with Peering Connections
Medium6.5Mar 9, 2023
HashiCorp Consul vulnerable to authorization bypass
Medium6.5Sep 25, 2022
HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions
High7.1Sep 25, 2022
HashiCorp Consul Cross-site Scripting vulnerability
Medium6.1May 24, 2022
HashiCorp Consul can use cleartext agent-to-agent RPC communication
Medium5.9May 14, 2022
HashiCorp Consul vulnerable to Origin Validation Error
High7.4May 13, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.