Hashicorp

Consul

48 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 10.09.2026 19:17:39
  • Zuletzt bearbeitet 10.09.2026 20:17:31

Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul di...

  • EPSS 0.23%
  • Veröffentlicht 10.09.2026 19:17:37
  • Zuletzt bearbeitet 10.09.2026 20:17:29

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permission may explo...

  • EPSS 0.24%
  • Veröffentlicht 10.09.2026 18:55:15
  • Zuletzt bearbeitet 10.09.2026 19:45:14

Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal RPC mTLS hand...

  • EPSS 0.21%
  • Veröffentlicht 10.09.2026 18:54:45
  • Zuletzt bearbeitet 10.09.2026 19:45:14

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker with a token gra...

  • EPSS 0.29%
  • Veröffentlicht 07.08.2026 19:20:32
  • Zuletzt bearbeitet 28.08.2026 15:47:00

Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cause the agent to consume substantial memory before the request was ...

  • EPSS 0.39%
  • Veröffentlicht 07.08.2026 19:20:22
  • Zuletzt bearbeitet 28.08.2026 15:47:00

Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors, g...

  • EPSS 0.16%
  • Veröffentlicht 07.08.2026 19:20:13
  • Zuletzt bearbeitet 28.08.2026 15:47:00

Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach HTTP paths that are ...

  • EPSS 0.33%
  • Veröffentlicht 07.08.2026 19:19:20
  • Zuletzt bearbeitet 28.08.2026 15:47:00

Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with `operator:write` ...

  • EPSS 0.29%
  • Veröffentlicht 07.08.2026 19:19:11
  • Zuletzt bearbeitet 28.08.2026 15:47:00

Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow the agent's Connect CA roots cache without bound, ...

  • EPSS 0.26%
  • Veröffentlicht 07.08.2026 19:19:05
  • Zuletzt bearbeitet 28.08.2026 15:47:00

Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow the agent's intention-match cache without bound, de...