GO-2022-1029
Dashboard / Vulnerabilities / GO-2022-1029
Summary: HashiCorp Consul vulnerable to authorization bypass in github.com/hashicorp/consul
Details: HashiCorp Consul vulnerable to authorization bypass in github.com/hashicorp/consul
References: https://github.com/advisories/GHSA-m69r-9g56-7mv8, https://nvd.nist.gov/vuln/detail/CVE-2022-40716, https://github.com/hashicorp/consul/commit/8f6fb4f6fe9488b8ec37da71ac503081d7d3760b, https://github.com/hashicorp/consul/pull/14579, https://discuss.hashicorp.com, https://discuss.hashicorp.com/t/hcsec-2022-20-consul-service-mesh-intention-bypass-with-malicious-certificate-signing-request/44628, https://lists.fedoraproject.org/archives/list/[email protected]/message/LYZOKMMVX4SIEHPJW3SJUQGMO5YZCPHC, https://lists.fedoraproject.org/archives/list/[email protected]/message/ZTE4ITXXPIWZEQ4HYQCB6N6GZIMWXDAI
Affected packages
Package
Name: github.com/hashicorp/consul
Purl: pkg:golang/github.com/hashicorp/consul
Affected ranges
Type: SEMVER
Events:
