Allocation of Resources Without Limits or Throttling in Hashicorp Consul
High severity
GitHub Reviewed
Published
May 18, 2021
to the GitHub Advisory Database
•
Updated Oct 2, 2023
Package
Affected versions
>= 1.2.0, < 1.6.6
>= 1.7.0, < 1.7.4
Patched versions
1.6.6
1.7.4
Description
Published by the National Vulnerability Database
Jun 11, 2020
Reviewed
May 12, 2021
Published to the GitHub Advisory Database
May 18, 2021
Last updated
Oct 2, 2023
HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to denial of service.
Specific Go Packages Affected
github.com/hashicorp/consul/agent/config
Fix
The vulnerability is fixed in versions 1.6.6 and 1.7.4.
References