Lucene search

K
osvGoogleOSV:GHSA-HJ93-5FG3-3CHR
HistoryFeb 25, 2022 - 12:01 a.m.

HashiCorp Consul Ingress Gateway Panic Can Shutdown Servers

2022-02-2500:01:01
Google
osv.dev
21
hashicorp consul
consul enterprise
uncontrolled resource consumption
ingress gateway
shutdown
security vulnerability

EPSS

0.002

Percentile

60.9%

HashiCorp Consul and Consul Enterprise 1.8.0 through 1.9.14, 1.10.7, and 1.11.2 has Uncontrolled Resource Consumption. Clusters with at least one ingress gateway configured may allow a user with service:write permission to register a specifically-defined service that can cause the Consul server to panic and shutdown. Versions 1.9.15, 1.10.8, and 1.11.3 contain patches for the problem.