HashiCorp Consul Ingress Gateway Panic Can Shutdown Servers
Moderate severity
GitHub Reviewed
Published
Feb 25, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Package
Affected versions
>= 1.8.0, <= 1.9.14
>= 1.10.0, <= 1.10.7
>= 1.11.0, <= 1.11.2
Patched versions
1.9.15
1.10.8
1.11.3
Description
Published by the National Vulnerability Database
Feb 24, 2022
Published to the GitHub Advisory Database
Feb 25, 2022
Reviewed
Aug 18, 2022
Last updated
Jan 30, 2023
HashiCorp Consul and Consul Enterprise 1.8.0 through 1.9.14, 1.10.7, and 1.11.2 has Uncontrolled Resource Consumption. Clusters with at least one ingress gateway configured may allow a user with
service:write
permission to register a specifically-defined service that can cause the Consul server to panic and shutdown. Versions 1.9.15, 1.10.8, and 1.11.3 contain patches for the problem.References