ConsulGHSA-q2qr-3c2p-9235
Denial of Service (DoS) in HashiCorp Consul
Medium5.3CVE-2020-12758 · Published Feb 15, 2022 · updated Aug 21, 2024
HashiCorp Consul and Consul Enterprise could crash when configured with an abnormally-formed service-router entry. Introduced in 1.6.0, fixed in 1.6.6 and 1.7.4. ### Specific Go Packages Affected github.com/hashicorp/consul/agent/consul/discoverychain
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/consul Go | >= 1.6.0-beta1, < 1.6.6 | 1.6.6 |
| >= 1.7.0, < 1.7.4 | 1.7.4 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-400
- Also known as
- BIT-consul-2020-12758, CVE-2020-12758, GO-2022-0861
More Consul advisories
All Consul| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 242022 | HashiCorp Consul Cross-site Scripting vulnerability | Medium6.1 | 1.7.14+2 more |
| May 142022 | HashiCorp Consul can use cleartext agent-to-agent RPC communication | Medium5.9 | 1.4.1 |
| May 132022 | HashiCorp Consul vulnerable to Origin Validation Error | High7.4 | 1.4.4 |
| May 132022 | HashiCorp Consul Access Restriction Bypass | High8.1 | 1.4.3 |
| Apr 202022 | Hashicorp Consul HTTP health check endpoints returning an HTTP redirect may be abused as SSRF vector | High7.5 | 1.9.17+2 more |
| Feb 252022 | HashiCorp Consul Ingress Gateway Panic Can Shutdown Servers | Medium6.5 | 1.9.15+2 more |