HIGH7.4
GHSA-q7fx-wm2p-qfj8
HashiCorp Consul vulnerable to Origin Validation Error
Quick fix
GHSA-q7fx-wm2p-qfj8 — github.com/hashicorp/consul: upgrade to the fixed version with the command below.
go get github.com/hashicorp/consul@v1.4.4Details
HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if `verify_server_hostname` were set to false, even when it is actually set to true. This is fixed in 1.4.4.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/consul
Introduced in:
0Fixed in: 1.4.4Fix
go get github.com/hashicorp/consul@v1.4.4