Denial of Service (DoS) in HashiCorp Consul
Moderate severity
GitHub Reviewed
Published
Feb 15, 2022
to the GitHub Advisory Database
•
Updated Oct 2, 2023
Package
Affected versions
>= 1.6.0-beta1, < 1.6.6
>= 1.7.0, < 1.7.4
Patched versions
1.6.6
1.7.4
Description
Reviewed
May 13, 2021
Published to the GitHub Advisory Database
Feb 15, 2022
Last updated
Oct 2, 2023
HashiCorp Consul and Consul Enterprise could crash when configured with an abnormally-formed service-router entry. Introduced in 1.6.0, fixed in 1.6.6 and 1.7.4.
Specific Go Packages Affected
github.com/hashicorp/consul/agent/consul/discoverychain
References