Asymmetric denial of service In github.com/hashicorp/consul/config
Description
Allocation of Resources Without Limits or Throttling in Hashicorp Consul HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to denial of service.
Specific Go Packages Affected
github.com/hashicorp/consul/agent/config
Fix
The vulnerability is fixed in versions 1.6.6 and 1.7.4.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | v1.6.6, v1.7.4 | ||
debian 11 | 1.7.4+dfsg1-1 | ||
go | 1.6.6, 1.7.4 | ||
go | 1.6.6, 1.7.4 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4.