CVE-2020-12758: High severity hashicorp consul vulnerability
Published Jun 11, 2020
·Updated
HashiCorp Consul and Consul Enterprise could crash when configured with an abnormally-formed service-router entry. Introduced in 1.6.0, fixed in 1.6.6 and 1.7.4.
Affected Software
4 affected componentsFixes available
go/github.com/hashicorp/consul>=1.7.0<1.7.4
1.7.4
go/github.com/hashicorp/consul>=1.6.0-beta1<1.6.6
1.6.6
Hashicorp Consul>=1.6.0<1.6.6
Hashicorp Consul>=1.6.0<1.6.6
Remediation
Patch Available
Event History
Jun 11, 2020
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
Description
Feb 15, 2022
Advisory Published
01:57 AM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-12758.
2
What is the severity of CVE-2020-12758?
The severity of CVE-2020-12758 is high (7.5).
3
How can HashiCorp Consul and Consul Enterprise be affected by CVE-2020-12758?
HashiCorp Consul and Consul Enterprise can crash when configured with an abnormally-formed service-router entry.
4
Which versions of HashiCorp Consul and Consul Enterprise are affected by CVE-2020-12758?
Versions between 1.6.0-beta1 and 1.6.6 for Consul, and between 1.7.0 and 1.7.4 for Consul Enterprise.
5
How can I fix CVE-2020-12758?
To fix CVE-2020-12758, you should upgrade to version 1.6.6 for Consul or version 1.7.4 for Consul Enterprise.