HIGH
HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes
Published Nov 4, 2020
7.5
HIGHCVSS 3.1
EPSS 2.61%
Description
HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7.9 and 1.8.5.
Affected products
No data.
No data.
No Red Hat product state for this CVE.
github.com/hashicorp/consul
Go
Introduced 1.7.0 Fixed 1.7.9github.com/hashicorp/consul
Go
Introduced 1.8.0 Fixed 1.8.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/hashicorp/consul | 1.7.0 | 1.7.9 |
| Go | github.com/hashicorp/consul | 1.8.0 | 1.8.5 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-0243 Advisory
- https://github.com/advisories/GHSA-496g-fr33-whrf Advisory
- https://github.com/hashicorp/consul/blob/master/CHANGELOG.md#185-october-23-2020 x_refsource_CONFIRMVendor Advisory
- https://github.com/hashicorp/consul/pull/9024
- https://github.com/hashicorp/consul/releases/tag/v1.8.5
- https://nvd.nist.gov/vuln/detail/CVE-2020-25201
- https://security.gentoo.org/glsa/202208-09 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.hashicorp.com/blog/category/consul x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-0243 | Advisory | |
| https://github.com/advisories/GHSA-496g-fr33-whrf | Advisory | |
| https://github.com/hashicorp/consul/blob/master/CHANGELOG.md#185-october-23-2020 | x_refsource_CONFIRMVendor Advisory | |
| https://github.com/hashicorp/consul/pull/9024 | ||
| https://github.com/hashicorp/consul/releases/tag/v1.8.5 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2020-25201 | ||
| https://security.gentoo.org/glsa/202208-09 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://www.hashicorp.com/blog/category/consul | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 4, 2020
Updated Aug 4, 2024
Reserved Sep 4, 2020
Link CVE-2020-25201
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2024-0243 GHSA-496G-FR33-WHRF Assigner mitre
Published Nov 4, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2024-0243