Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-29153 PoC — HashiCorp Consul 代码问题漏洞

Source
Associated Vulnerability
Title:HashiCorp Consul 代码问题漏洞 (CVE-2022-29153)
Description:Hashicorp HashiCorp Consul是美国Hashicorp公司的一套分布式、高可用数据中心感知解决方案。该产品用于跨动态分布式基础架构连接和配置应用程序。 HashiCorp Consul 和 Consul Enterprise 存在代码问题漏洞,目前暂无该漏洞信息,请随时关注CNNVD或厂商公告。
Description
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11 are susceptible to server-side request forgery. When redirects are returned by HTTP health check endpoints, Consul follows these HTTP redirects by default. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
File Snapshot

id: CVE-2022-29153 info: name: HashiCorp Consul/Consul Enterprise - Server-Side Request Forgery ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.