VDB
Sign up
MEDIUM6.1

GHSA-8xmx-h8rq-h94j

HashiCorp Consul Cross-site Scripting vulnerability

Quick fix

GHSA-8xmx-h8rq-h94j — github.com/hashicorp/consul: upgrade to the fixed version with the command below.

go get github.com/hashicorp/consul@v1.9.5

Details

HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scripting. Fixed in 1.9.5, 1.8.10 and 1.7.14.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/consul
Introduced in: 1.9.0Fixed in: 1.9.5
Fixgo get github.com/hashicorp/consul@v1.9.5
Go/github.com/hashicorp/consul
Introduced in: 1.8.0Fixed in: 1.8.10
Fixgo get github.com/hashicorp/consul@v1.8.10
Go/github.com/hashicorp/consul
Introduced in: 0Fixed in: 1.7.14
Fixgo get github.com/hashicorp/consul@v1.7.14

References