CVE-2020-25201: High severity hashicorp consul vulnerability
HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7.9 and 1.8.5.
Other sources
HashiCorp Consul Enterprise versions 1.7.0 up to 1.7.8 and 1.8.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7.9 and 1.8.5.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-25201.
Which version of HashiCorp Consul Enterprise is affected?
HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 is affected.
What is the severity of CVE-2020-25201?
The severity of CVE-2020-25201 is high with a CVSS score of 7.5.
How can CVE-2020-25201 be exploited?
CVE-2020-25201 can be exploited by triggering a namespace replication bug to cause denial of service via infinite Raft writes.
How can I fix CVE-2020-25201?
CVE-2020-25201 can be fixed by upgrading to version 1.7.9 or 1.8.5 of HashiCorp Consul Enterprise.