Lucene search

K
osvGoogleOSV:GHSA-RQJQ-MRGX-85HP
HistoryMay 18, 2021 - 6:21 p.m.

Allocation of Resources Without Limits or Throttling in Hashicorp Consul

2021-05-1818:21:35
Google
osv.dev
9

7.3 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.2%

HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to denial of service.

Specific Go Packages Affected

github.com/hashicorp/consul/agent/config

Fix

The vulnerability is fixed in versions 1.6.6 and 1.7.4.

7.3 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.2%