CVE-2022-29153
Dashboard / Vulnerabilities / CVE-2022-29153
Summary:
Details: HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.
References: https://discuss.hashicorp.com, https://discuss.hashicorp.com/t/hcsec-2022-10-consul-s-http-health-check-may-allow-server-side-request-forgery/, https://discuss.hashicorp.com/t/hcsec-2022-10-consul-s-http-health-check-may-allow-server-side-request-forgery/38393, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29153.json, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RBODKZL7HQE5XXS3SA2VIDVL4LAA5RWH/, https://nvd.nist.gov/vuln/detail/CVE-2022-29153, https://security.gentoo.org/glsa/202208-09, https://security.netapp.com/advisory/ntap-20220602-0005/
Affected packages
Package
Name:
Purl:
