First published: Wed Nov 04 2020(Updated: )
HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7.9 and 1.8.5.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Consul | >=1.7.0<=1.8.4 | |
go/github.com/hashicorp/consul | >=1.8.0<1.8.5 | 1.8.5 |
go/github.com/hashicorp/consul | >=1.7.0<1.7.9 | 1.7.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-25201.
HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 is affected.
The severity of CVE-2020-25201 is high with a CVSS score of 7.5.
CVE-2020-25201 can be exploited by triggering a namespace replication bug to cause denial of service via infinite Raft writes.
CVE-2020-25201 can be fixed by upgrading to version 1.7.9 or 1.8.5 of HashiCorp Consul Enterprise.