Skip to content
ConsulGHSA-rqjq-mrgx-85hp

Allocation of Resources Without Limits or Throttling in Hashicorp Consul

High7.5CVE-2020-13250 · Published May 18, 2021 · updated Aug 21, 2024

HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to denial of service. ### Specific Go Packages Affected github.com/hashicorp/consul/agent/config ### Fix The vulnerability is fixed in versions 1.6.6 and 1.7.4.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
>= 1.2.0, < 1.6.61.6.6
>= 1.7.0, < 1.7.41.7.4
Details and references

More Consul advisories

All Consul
Advisory
Incorrect Authorization in HashiCorp Consul
Medium5.3Jul 28, 2021
HashiCorp Consul L7 deny intention results in an allow action
High7.5Jul 19, 2021
Hashicorp Consul Missing SSL Certificate Validation
High7.5Jul 19, 2021
Incorrect Permission Assignment for Critical Resource in Hashicorp Consul
Medium5.3Jun 23, 2021
Improper Input Validation in HashiCorp Consul
Medium5.3May 18, 2021
Denial of Service (DoS) in HashiCorp Consul
High7.5May 18, 2021

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.