QID 997920

Date Published: 2024-04-03

QID 997920: GO (Go) Security Update for github.com/hashicorp/consul (GHSA-hr3v-8cp3-68rf)

HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 did not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.1 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-hr3v-8cp3-68rf for updates and patch information.
    Vendor References

    CVEs related to QID 997920

    Software Advisories
    Advisory ID Software Component Link
    GHSA-hr3v-8cp3-68rf github.com/hashicorp/consul URL Logo github.com/advisories/GHSA-hr3v-8cp3-68rf