consulGHSA-hj93-5fg3-3chr
HashiCorp Consul Ingress Gateway Panic Can Shutdown Servers
Medium6.5CVE-2022-24687 · Published Feb 25, 2022 · updated Aug 21, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/consul Go | >= 1.8.0, < 1.9.15 | 1.9.15 |
| >= 1.10.0, < 1.10.8 | 1.10.8 | |
| >= 1.11.0, < 1.11.3 | 1.11.3 |
Details and references
HashiCorp Consul and Consul Enterprise 1.8.0 through 1.9.14, 1.10.7, and 1.11.2 has Uncontrolled Resource Consumption. Clusters with at least one ingress gateway configured may allow a user with `service:write` permission to register a specifically-defined service that can cause the Consul server to panic and shutdown. Versions 1.9.15, 1.10.8, and 1.11.3 contain patches for the problem.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-400
- Also known as
- BIT-consul-2022-24687, CVE-2022-24687, GO-2022-0953
More consul advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 152022 | Denial of Service (DoS) in HashiCorp Consul CVE-2020-12758Medium5.3fixed in 1.6.6, 1.7.4 | Medium5.3 | 1.6.6, 1.7.4 |
| Apr 202022 | Hashicorp Consul HTTP health check endpoints returning an HTTP redirect may be abused as SSRF vector CVE-2022-29153High7.5fixed in 1.9.17, 1.10.10, 1.11.5 | High7.5 | 1.9.17, 1.10.10, 1.11.5 |
| May 132022 | HashiCorp Consul Access Restriction Bypass CVE-2019-8336High8.1fixed in 1.4.3 | High8.1 | 1.4.3 |
| May 132022 | HashiCorp Consul vulnerable to Origin Validation Error CVE-2019-9764High7.4fixed in 1.4.4 | High7.4 | 1.4.4 |
| May 142022 | HashiCorp Consul can use cleartext agent-to-agent RPC communication CVE-2018-19653Medium5.9fixed in 1.4.1 | Medium5.9 | 1.4.1 |
| May 242022 | HashiCorp Consul Cross-site Scripting vulnerability CVE-2020-25864Medium6.1fixed in 1.7.14, 1.8.10, 1.9.5 | Medium6.1 | 1.7.14, 1.8.10, 1.9.5 |