HashiCorp Consul是美国HashiCorp公司的一套分布式、高可用数据中心感知解决方案。该产品用于跨动态分布式基础架构连接和配置应用程序。 HashiCorp Consul存在安全漏洞,该漏洞源于在 L7 流量意图中使用 URL 路径可以绕过基于 HTTP 请求路径的访问规则。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HashiCorp | Consul | 1.9.0 ~ 1.20.1 | - |
|
| HashiCorp | Consul Enterprise | 1.9.0 ~ 1.20.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-10006 | 8.3 HIGH | Consul L7 Intentions Vulnerable To Headers Bypass |
| CVE-2024-10086 | 6.1 MEDIUM | Consul Vulnerable To Reflected XSS On Content-Type Error Manipulation |
No comments yet