7.5
CVSSv3

CVE-2022-29153

Published: 19/04/2022 Updated: 23/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hashicorp consul

fedoraproject fedora 37

Vendor Advisories

Debian Bug report logs - #1015218 consul: CVE-2021-37219 CVE-2021-38698 CVE-2022-29153 Package: src:consul; Maintainer for src:consul is Debian Go Packaging Team <pkg-go-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sun, 17 Jul 2022 20:03:02 UTC Severity: grave Tags: sec ...
Debian Bug report logs - #1017982 consul: CVE-2022-29153 Package: src:consul; Maintainer for src:consul is Debian Go Packaging Team <pkg-go-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sun, 17 Jul 2022 20:03:02 UTC Severity: grave Tags: security, upstream Reply or ...