logo

CVE-2019-9764 github.com/hashicorp/consul

Package

Manager: go
Name: github.com/hashicorp/consul
Vulnerable Version: >=0 <1.4.4

Severity

Level: High

CVSS v3.1: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00183 pctl0.40277

Details

HashiCorp Consul vulnerable to Origin Validation Error HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if `verify_server_hostname` were set to false, even when it is actually set to true. This is fixed in 1.4.4.

Metadata

Created: 2022-05-13T01:23:06Z
Modified: 2023-06-09T23:23:59Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-q7fx-wm2p-qfj8/GHSA-q7fx-wm2p-qfj8.json
CWE IDs: ["CWE-346"]
Alternative ID: GHSA-q7fx-wm2p-qfj8
Finding: F086
Auto approve: 1