CVE Vulnerabilities

CVE-2022-24687

Published: Feb 24, 2022 | Modified: Aug 08, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:write to register a specifically-defined service that can cause Consul servers to panic. Fixed in 1.9.15, 1.10.8, and 1.11.3.

Affected Software

Name Vendor Start Version End Version
Consul Hashicorp 1.8.0 (including) 1.9.15 (excluding)
Consul Hashicorp 1.10.0 (including) 1.10.8 (excluding)
Consul Hashicorp 1.11.0 (including) 1.11.3 (excluding)

References