MEDIUM4.9
GHSA-c57c-7hrj-6q6v
Hashicorp Consul vulnerable to denial of service
Quick fix
GHSA-c57c-7hrj-6q6v — github.com/hashicorp/consul: upgrade to the fixed version with the command below.
go get github.com/hashicorp/consul@v1.14.5Details
Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial of service. This vulnerability was resolved in Consul 1.14.5, and 1.15.3
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/consul
Introduced in:
0Fixed in: 1.14.5Fix
go get github.com/hashicorp/consul@v1.14.5Go/github.com/hashicorp/consul
Introduced in:
1.15.0Fixed in: 1.15.3Fix
go get github.com/hashicorp/consul@v1.15.3