Lucene search

K
osvGoogleOSV:CVE-2022-24687
HistoryFeb 24, 2022 - 4:15 p.m.

CVE-2022-24687

2022-02-2416:15:08
Google
osv.dev
17
hashicorp consul
consul enterprise
unauthorized service registration
server panic

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

60.9%

HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:write to register a specifically-defined service that can cause Consul servers to panic. Fixed in 1.9.15, 1.10.8, and 1.11.3.

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

60.9%