CVE-2018-19653: Medium severity hashicorp consul vulnerability
Published Dec 9, 2018
·Updated
HashiCorp Consul 0.5.1 through 1.4.0 can use cleartext agent-to-agent RPC communication because the verifyoutgoing setting is improperly documented. NOTE: the vendor has provided reconfiguration steps that do not require a software upgrade.
Affected Software
1 affected component
Hashicorp Consul>=0.5.1<=1.4.0
Remediation
Patch Available
Event History
Dec 9, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this HashiCorp Consul vulnerability?
The vulnerability ID for this HashiCorp Consul vulnerability is CVE-2018-19653.
2
What is the severity of CVE-2018-19653?
The severity of CVE-2018-19653 is medium with a severity value of 5.9.
3
What is affected by CVE-2018-19653?
HashiCorp Consul versions 0.5.1 through 1.4.0 are affected by CVE-2018-19653.
4
What is the issue with HashiCorp Consul 0.5.1 through 1.4.0?
HashiCorp Consul 0.5.1 through 1.4.0 can use cleartext agent-to-agent RPC communication because the verify_outgoing setting is improperly documented.
5
How can CVE-2018-19653 be mitigated?
CVE-2018-19653 can be mitigated by following the reconfiguration steps provided by the vendor that do not require a software upgrade.