First published: Thu Feb 24 2022(Updated: )
HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:write to register a specifically-defined service that can cause Consul servers to panic. Fixed in 1.9.15, 1.10.8, and 1.11.3.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Consul | >=1.8.0<1.9.15 | |
HashiCorp Consul | >=1.8.0<1.9.15 | |
HashiCorp Consul | >=1.10.0<1.10.8 | |
HashiCorp Consul | >=1.10.0<1.10.8 | |
HashiCorp Consul | >=1.11.0<1.11.3 | |
HashiCorp Consul | >=1.11.0<1.11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24687 is a vulnerability in HashiCorp Consul and Consul Enterprise versions 1.9.0 through 1.9.14, 1.10.7, and 1.11.2.
CVE-2022-24687 has a severity rating of 6.5, which is considered medium.
HashiCorp Consul and Consul Enterprise versions 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 are affected by CVE-2022-24687.
To fix CVE-2022-24687, upgrade to a patched version of HashiCorp Consul or Consul Enterprise, specifically versions 1.9.15, 1.10.8, or 1.11.3.
More information about CVE-2022-24687 can be found on the HashiCorp discussion forum and the Gentoo security advisory page.