HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.
References
Link | Resource |
---|---|
https://discuss.hashicorp.com/t/hcsec-2022-28-consul-cluster-peering-leaks-imported-nodes-services-information/46946 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: HashiCorp
Published: 2022-11-15T23:25:30.161Z
Updated:
Reserved: 2022-11-09T23:10:38.071Z
Link: CVE-2022-3920
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-11-16T00:15:09.747
Modified: 2022-11-18T20:21:33.360
Link: CVE-2022-3920
JSON object: View
Redhat Information
No data.
CWE