VDB
Sign up
MEDIUM6.1

GHSA-99wr-c2px-grmh

Hashicorp Consul Cross-site Scripting vulnerability

Quick fix

GHSA-99wr-c2px-grmh — github.com/hashicorp/consul: upgrade to the fixed version with the command below.

go get github.com/hashicorp/consul@v1.20.0

Details

A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/consul
Introduced in: 1.4.1Fixed in: 1.20.0
Fixgo get github.com/hashicorp/consul@v1.20.0

References