CVE-2022-29153

NameCVE-2022-29153
DescriptionHashiCorp Consul and Consul Enterprise through 2022-04-12 allow SSRF.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
consul (PTS)buster1.0.7~dfsg1-5vulnerable
bullseye1.8.7+dfsg1-2vulnerable
bookworm, sid1.8.7+dfsg1-5vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
consulsource(unstable)(unfixed)

Notes

https://discuss.hashicorp.com/t/hcsec-2022-10-consul-s-http-health-check-may-allow-server-side-request-forgery/38393

Search for package or bug name: Reporting problems