CVE-2020-13250
Summary
| CVE | CVE-2020-13250 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-11 20:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to denial of service. Fixed in 1.6.6 and 1.7.4. |
Risk And Classification
Problem Types: CWE-770
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| consul/CHANGELOG.md at v1.6.6 · hashicorp/consul · GitHub | CONFIRM | github.com | Release Notes, Third Party Advisory |
| CVE-2020-13250: Cache DoS / OOM by i0rek · Pull Request #8023 · hashicorp/consul · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| consul/CHANGELOG.md at v1.7.4 · hashicorp/consul · GitHub | CONFIRM | github.com | Release Notes, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981877 Go (go) Security Update for github.com/hashicorp/consul/agent/config (GHSA-rqjq-mrgx-85hp)