Asymmetric denial of service In github.com/hashicorp/consul/acl
Description
Denial of service in HashiCorp Consul HashiCorp Consul Enterprise versions 1.7.0 up to 1.7.8 and 1.8.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7.9 and 1.8.5.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | v1.8.5 | ||
go | 1.7.9, 1.8.5 | ||
debian 11 | 1.8.6+dfsg1-1 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4.