Hashicorp HashiCorp Consul是美国Hashicorp公司的一套分布式、高可用数据中心感知解决方案。该产品用于跨动态分布式基础架构连接和配置应用程序。 HashiCorp Consul 和 Consul Enterprise 存在代码问题漏洞,目前暂无该漏洞信息,请随时关注CNNVD或厂商公告。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11 are susceptible to server-side request forgery. When redirects are returned by HTTP health check endpoints, Consul follows these HTTP redirects by default. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-29153.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-25648 | 8.1 HIGH | Command Injection |
| CVE-2022-27527 | Autodesk Navisworks 缓冲区错误漏洞 | |
| CVE-2022-25788 | Autodesk AutoCAD 缓冲区错误漏洞 | |
| CVE-2022-27104 | FormaLms SQL注入漏洞 | |
| CVE-2022-27055 | ecjia-daojia 安全漏洞 | |
| CVE-2021-44519 | Citrix XenMobile Server 路径遍历漏洞 | |
| CVE-2022-29315 | Invicti Acunetix 安全漏洞 | |
| CVE-2022-26595 | Liferay Portal和Liferay DXP 安全漏洞 | |
| CVE-2022-26593 | Liferay Portal和Liferay DXP 跨站脚本漏洞 | |
| CVE-2021-41570 | Veritas NetBackup 跨站脚本漏洞 | |
| CVE-2022-27927 | Microfinance Management System SQL注入漏洞 | |
| CVE-2021-43129 | Desire2Learn Learning Management System 安全漏洞 | |
| CVE-2022-28108 | Selenium Server 跨站请求伪造漏洞 |
No comments yet