CVE Vulnerabilities

CVE-2022-24687

Published: Feb 24, 2022 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:write to register a specifically-defined service that can cause Consul servers to panic. Fixed in 1.9.15, 1.10.8, and 1.11.3.

Affected Software

Name Vendor Start Version End Version
Consul Hashicorp 1.8.0 (including) 1.9.15 (excluding)
Consul Hashicorp 1.10.0 (including) 1.10.8 (excluding)
Consul Hashicorp 1.11.0 (including) 1.11.3 (excluding)
Consul Ubuntu bionic *
Consul Ubuntu impish *
Consul Ubuntu kinetic *
Consul Ubuntu trusty *
Consul Ubuntu xenial *

References