consul: specially crafted KV entry could be used to perform a XSS attack
Published Apr 20, 2021
6.1
MEDIUMCVSS 3.1
EPSS 6.07%
Description
HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scripting. Fixed in 1.9.5, 1.8.10 and 1.7.14.
Affected products
No data.
No data.
OpenShift Service Mesh 2.0
servicemesh
Not affected
OpenShift Service Mesh 2.0
servicemesh-prometheus
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/metrics-collector-rhel8
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/multicluster-observability-rhel9-operator
Not affected
Red Hat Fuse 7
consul-client
Not affected
Red Hat OpenShift Container Platform 4
openshift4-wincw/windows-machine-config-rhel8-operator
Not affected
Red Hat OpenShift Container Platform 4
openshift4/cnf-tests-rhel8
Not affected
Red Hat OpenShift Container Platform 4
openshift4/compliance-rhel8-operator
Not affected
Red Hat OpenShift Container Platform 4
openshift4/file-integrity-rhel8-operator
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-baremetal-machine-controllers-rhel9
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-cluster-etcd-rhel9-operator
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-cluster-node-tuning-operator
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-cluster-node-tuning-rhel9-operator
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-operator-registry
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-prometheus
Not affected
Red Hat OpenShift Virtualization 4
container-native-virtualization/hostpath-provisioner-rhel8-operator
Not affected
Red Hat OpenShift Virtualization 4
container-native-virtualization/hyperconverged-cluster-operator
Not affected
Red Hat OpenShift Virtualization 4
container-native-virtualization/hyperconverged-cluster-webhook-rhel8
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 2.0 | servicemesh | Not affected | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-prometheus | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/metrics-collector-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/multicluster-observability-rhel9-operator | Not affected | n/a |
| Red Hat Fuse 7 | consul-client | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4-wincw/windows-machine-config-rhel8-operator | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/cnf-tests-rhel8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/compliance-rhel8-operator | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/file-integrity-rhel8-operator | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-baremetal-machine-controllers-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-etcd-rhel9-operator | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-node-tuning-operator | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-node-tuning-rhel9-operator | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-operator-registry | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-prometheus | Not affected | n/a |
| Red Hat OpenShift Virtualization 4 | container-native-virtualization/hostpath-provisioner-rhel8-operator | Not affected | n/a |
| Red Hat OpenShift Virtualization 4 | container-native-virtualization/hyperconverged-cluster-operator | Not affected | n/a |
| Red Hat OpenShift Virtualization 4 | container-native-virtualization/hyperconverged-cluster-webhook-rhel8 | Not affected | n/a |
github.com/hashicorp/consul
Go
Introduced 1.9.0 Fixed 1.9.5github.com/hashicorp/consul
Go
Introduced 1.8.0 Fixed 1.8.10github.com/hashicorp/consul
Go
Introduced 0 Fixed 1.7.14
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/hashicorp/consul | 1.9.0 | 1.9.5 |
| Go | github.com/hashicorp/consul | 1.8.0 | 1.8.10 |
| Go | github.com/hashicorp/consul | 0 | 1.7.14 |
Remediation
Red Hat statement
OpenShift Container Platform (OCP) and OpenShift Service Mesh (OSSM) components ship only consul api which could be used for connection to consul service mesh solution, therefore are not affected by this flaw. Some OpenShift Virtualization components reference consul in go.sum files, however none of the projects or container images depend on or ship consul, therefore are not affected by this flaw.
References (10)
- https://access.redhat.com/security/cve/CVE-2020-25864 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1950275 Issue Tracking
- https://discuss.hashicorp.com/t/hcsec-2021-07-consul-api-kv-endpoint-vulnerable-to-cross-site-scripting/23368 x_refsource_MISCVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-3260 Advisory
- https://github.com/advisories/GHSA-8xmx-h8rq-h94j Advisory
- https://github.com/hashicorp/consul/pull/10023
- https://nvd.nist.gov/vuln/detail/CVE-2020-25864
- https://security.gentoo.org/glsa/202208-09 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-25864
- https://www.hashicorp.com/blog/category/consul x_refsource_MISCProductVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-25864 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1950275 | Issue Tracking | |
| https://discuss.hashicorp.com/t/hcsec-2021-07-consul-api-kv-endpoint-vulnerable-to-cross-site-scripting/23368 | x_refsource_MISCVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-3260 | Advisory | |
| https://github.com/advisories/GHSA-8xmx-h8rq-h94j | Advisory | |
| https://github.com/hashicorp/consul/pull/10023 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2020-25864 | ||
| https://security.gentoo.org/glsa/202208-09 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-25864 | ||
| https://www.hashicorp.com/blog/category/consul | x_refsource_MISCProductVendor Advisory |
Change history (0)
No recorded changes yet.