Show filters
55 Total Results
Displaying 21-30 of 55
Sort by:
Attacker Value
Unknown
CVE-2023-0845
Disclosure Date: March 09, 2023 (last updated October 08, 2023)
Consul and Consul Enterprise allowed an authenticated user with service:write permissions to trigger a workflow that causes Consul server and client agents to crash under certain circumstances. This vulnerability was fixed in Consul 1.14.5.
0
Attacker Value
Unknown
CVE-2022-3920
Disclosure Date: November 16, 2022 (last updated December 22, 2024)
HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.
0
Attacker Value
Unknown
CVE-2022-40716
Disclosure Date: September 23, 2022 (last updated October 08, 2023)
HashiCorp Consul and Consul Enterprise up to 1.11.8, 1.12.4, and 1.13.1 do not check for multiple SAN URI values in a CSR on the internal RPC endpoint, enabling leverage of privileged access to bypass service mesh intentions. Fixed in 1.11.9, 1.12.5, and 1.13.2."
0
Attacker Value
Unknown
CVE-2021-41803
Disclosure Date: September 23, 2022 (last updated October 08, 2023)
HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2."
0
Attacker Value
Unknown
CVE-2022-38149
Disclosure Date: August 17, 2022 (last updated October 08, 2023)
HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault secret contents incorrectly. Fixed in 0.27.3, 0.28.3, and 0.29.2.
0
Attacker Value
Unknown
CVE-2022-29153
Disclosure Date: April 19, 2022 (last updated October 07, 2023)
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.
0
Attacker Value
Unknown
CVE-2022-24687
Disclosure Date: February 24, 2022 (last updated October 07, 2023)
HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:write to register a specifically-defined service that can cause Consul servers to panic. Fixed in 1.9.15, 1.10.8, and 1.11.3.
0
Attacker Value
Unknown
CVE-2021-41805
Disclosure Date: December 12, 2021 (last updated February 23, 2025)
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.
0
Attacker Value
Unknown
CVE-2021-38698
Disclosure Date: September 07, 2021 (last updated February 23, 2025)
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.
0
Attacker Value
Unknown
CVE-2021-37219
Disclosure Date: September 07, 2021 (last updated February 23, 2025)
HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.8.15, 1.9.9 and 1.10.2.
0