6.5
CVSSv3

CVE-2022-40716

Published: 23/09/2022 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

HashiCorp Consul and Consul Enterprise up to 1.11.8, 1.12.4, and 1.13.1 do not check for multiple SAN URI values in a CSR on the internal RPC endpoint, enabling leverage of privileged access to bypass service mesh intentions. Fixed in 1.11.9, 1.12.5, and 1.13.2."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hashicorp consul

Vendor Advisories

Debian Bug report logs - #1027161 consul: CVE-2022-40716 Package: src:consul; Maintainer for src:consul is Debian Go Packaging Team <pkg-go-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 28 Dec 2022 18:54:02 UTC Severity: important Tags: security, upstream Merged wit ...

Github Repositories

CG Images vs Docker Images w/Updated OS Packages Why not use popular Docker hub images, update all the OS packages, and call it a day? Target Images (2023-07-12) The analysis is completed on a set of popular Docker images: Popular official docker images Pull Rank Image Docker CG 1 alpine 2 nginx nginx:latest cgrdev/chainguard/nginx:latest 3 busybox busybox:lates