ConsulGHSA-q7fx-wm2p-qfj8
HashiCorp Consul vulnerable to Origin Validation Error
High7.4CVE-2019-9764 · Published May 13, 2022 · updated Sep 10, 2026
HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if `verify_server_hostname` were set to false, even when it is actually set to true. This is fixed in 1.4.4.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/consul Go | < 1.4.4 | 1.4.4 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-346
- Also known as
- CVE-2019-9764, GO-2023-1853
More Consul advisories
All Consul| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 242022 | HashiCorp Consul Cross-site Scripting vulnerability | Medium6.1 | 1.7.14+2 more |
| May 142022 | HashiCorp Consul can use cleartext agent-to-agent RPC communication | Medium5.9 | 1.4.1 |
| May 132022 | HashiCorp Consul Access Restriction Bypass | High8.1 | 1.4.3 |
| Apr 202022 | Hashicorp Consul HTTP health check endpoints returning an HTTP redirect may be abused as SSRF vector | High7.5 | 1.9.17+2 more |
| Feb 252022 | HashiCorp Consul Ingress Gateway Panic Can Shutdown Servers | Medium6.5 | 1.9.15+2 more |
| Feb 152022 | Denial of Service (DoS) in HashiCorp Consul | Medium5.3 | 1.6.6+1 more |