CVE-2020-7219: High severity Hashicorp Consul vulnerability
HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 1.6.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/hashicorp/consulto a version that resolves this vulnerability.Fixed in 1.6.3 - Upgrade
Upgrade
github.com/hashicorp/consul/agent/consulto a version that resolves this vulnerability.Fixed in 1.6.3
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-7219.
What is the severity of CVE-2020-7219?
The severity of CVE-2020-7219 is high, with a severity value of 7.5.
What is the affected software for CVE-2020-7219?
The affected software for CVE-2020-7219 is HashiCorp Consul and Consul Enterprise up to version 1.6.2.
How can I fix CVE-2020-7219?
You can fix CVE-2020-7219 by updating your HashiCorp Consul or Consul Enterprise to version 1.6.3.
Where can I find more information about CVE-2020-7219?
You can find more information about CVE-2020-7219 on the NIST National Vulnerability Database (NVD) website.