DirectorySecurity Advisories
Sign In
Security Advisories

CGA-2xjj-6666-9x77

Published

Last updated

https://images.chainguard.dev/security/CGA-2xjj-6666-9x77
Package

consul-1.17

Latest Update
Not affected
Aliases
  • CVE-2022-29153
  • GHSA-q6h7-4qgw-2j9p

Severity

7.5

High

CVSS V3

Summary

Hashicorp Consul HTTP health check endpoints returning an HTTP redirect may be abused as SSRF vector

Description

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that HTTP health check endpoints returning an HTTP redirect may be abused as a vector for server-side request forgery (SSRF). This vulnerability, CVE-2022-29153, was fixed in Consul 1.9.17, 1.10.10, and 1.11.5.

References

Updates


Safe Source for Open Source™
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images