HashiCorp Consul 1.2.2 Community Edition

CPE Details

HashiCorp Consul 1.2.2 Community Edition
1.2.2
2019-10-25
16h34 +00:00
2019-10-25
16h34 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:hashicorp:consul:1.2.2:*:*:*:community:*:*:*

Informations

Vendor

hashicorp

Product

consul

Version

1.2.2

Software Edition

community

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-13250 2020-06-11 17h16 +00:00 HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to denial of service. Fixed in 1.6.6 and 1.7.4.
7.5
High
CVE-2020-7219 2020-01-31 11h39 +00:00 HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 1.6.3.
7.5
High
CVE-2018-19653 2018-12-09 18h00 +00:00 HashiCorp Consul 0.5.1 through 1.4.0 can use cleartext agent-to-agent RPC communication because the verify_outgoing setting is improperly documented. NOTE: the vendor has provided reconfiguration steps that do not require a software upgrade.
5.9
Medium