HIGH
consul: HTTP/RPC Services Allow Unbounded Resource Usage
Published Jan 31, 2020
7.5
HIGHCVSS 3.1
EPSS 2.01%
Description
HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 1.6.3.
Affected products
No data.
No data.
OpenShift Service Mesh 1
servicemesh
Not affected
OpenShift Service Mesh 1
servicemesh-operator
Not affected
OpenShift Service Mesh 1
servicemesh-prometheus
Not affected
Red Hat Fuse 7
consul-client
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 1 | servicemesh | Not affected | n/a |
| OpenShift Service Mesh 1 | servicemesh-operator | Not affected | n/a |
| OpenShift Service Mesh 1 | servicemesh-prometheus | Not affected | n/a |
| Red Hat Fuse 7 | consul-client | Not affected | n/a |
github.com/hashicorp/consul
Go
Introduced 0 Fixed 1.6.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/hashicorp/consul | 0 | 1.6.3 |
Remediation
Red Hat mitigation
Enforce network connection limits on Consul server agents by using the following iptables rule: iptables -A INPUT -p tcp --syn --dport 8300 -m connlimit --connlimit-above 100 -j REJECT --reject-with tcp-reset.
References (7)
- https://access.redhat.com/security/cve/CVE-2020-7219 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1805866 Issue Tracking
- https://github.com/advisories/GHSA-23jv-v6qj-3fhh Advisory
- https://github.com/hashicorp/consul/issues/7159 x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7219
- https://www.cve.org/CVERecord?id=CVE-2020-7219
- https://www.hashicorp.com/blog/category/consul/ x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-7219 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1805866 | Issue Tracking | |
| https://github.com/advisories/GHSA-23jv-v6qj-3fhh | Advisory | |
| https://github.com/hashicorp/consul/issues/7159 | x_refsource_MISCThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7219 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-7219 | ||
| https://www.hashicorp.com/blog/category/consul/ | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 31, 2020
Updated Aug 4, 2024
Reserved Jan 17, 2020
Link CVE-2020-7219
CISA Vulnrichment
GHSA-23JV-V6QJ-3FHH Updated n/a