Back

MEDIUM

consul: specially crafted KV entry could be used to perform a XSS attack

Published Apr 20, 2021

Description

HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scripting. Fixed in 1.9.5, 1.8.10 and 1.7.14.

Affected products

Remediation

Red Hat statement

OpenShift Container Platform (OCP) and OpenShift Service Mesh (OSSM) components ship only consul api which could be used for connection to consul service mesh solution, therefore are not affected by this flaw. Some OpenShift Virtualization components reference consul in go.sum files, however none of the projects or container images depend on or ship consul, therefore are not affected by this flaw.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 20, 2021
Updated Aug 4, 2024
Reserved Sep 23, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 14, 2021
ENISA EUVD
Assigner mitre
Published Apr 20, 2021
Updated Aug 4, 2024
Exploited since n/a
EUVD-2022-3260 GHSA-8XMX-H8RQ-H94J