CVE-2022-29153
Published Apr 19, 2022
Last updated 2 years ago
Overview
- Description
- HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-918
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*", "vulnerable": true, "matchCriteriaId": "89112C2E-3AE8-45E3-8633-17F0174B47A3", "versionEndExcluding": "1.9.17" }, { "criteria": "cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "339A22E7-15BE-48B6-B10C-6D729F934B79", "versionEndExcluding": "1.9.17" }, { "criteria": "cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*", "vulnerable": true, "matchCriteriaId": "6EE5C7A3-A386-4B92-A943-A308729F73FF", "versionEndExcluding": "1.10.10", "versionStartIncluding": "1.10.0" }, { "criteria": "cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "D06A5FE9-9D57-4AB4-A681-29C8EC004AE9", "versionEndExcluding": "1.10.10", "versionStartIncluding": "1.10.0" }, { "criteria": "cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*", "vulnerable": true, "matchCriteriaId": "2C1E08E3-FBA8-4515-9B62-E3808C5B61E9", "versionEndExcluding": "1.11.5", "versionStartIncluding": "1.11.0" }, { "criteria": "cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "D731C85E-0913-4392-944F-85BCBD9EFF39", "versionEndExcluding": "1.11.5", "versionStartIncluding": "1.11.0" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E30D0E6F-4AE8-4284-8716-991DFA48CC5D" } ], "operator": "OR" } ] } ]