QID 981024
QID 981024: Go (go) Security Update for github.com/hashicorp/consul (GHSA-ccw8-7688-vqx4)
HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.8.15, 1.9.9 and 1.10.2.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-ccw8-7688-vqx4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-ccw8-7688-vqx4 -
github.com/advisories/GHSA-ccw8-7688-vqx4
CVEs related to QID 981024
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-ccw8-7688-vqx4 | github.com/hashicorp/consul |
|