7.5
CVSSv3

CVE-2022-3920

Published: 16/11/2022 Updated: 18/11/2022
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hashicorp consul

Vendor Advisories

Description<!---->A flaw was found in the Consul Package Affected versions of this package are vulnerable to information exposure via the /v1/internal/ui/nodes and /v1/internal/ui/services endpoints for cluster peering, which expose node and service information to unauthenticated attackersA flaw was found in the Consul Package Affected versions ...