Lucene search

K
osvGoogleOSV:GHSA-23JV-V6QJ-3FHH
HistoryMay 18, 2021 - 6:19 p.m.

Denial of Service (DoS) in HashiCorp Consul

2021-05-1818:19:21
Google
osv.dev
7

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.8%

HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 1.6.3.

Specific Go Packages Affected

github.com/hashicorp/consul/agent/consul

CPENameOperatorVersion
github.com/hashicorp/consullt1.6.3

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.8%