CVE Published: 15/11/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: HashiCorp |
Vendor: HashiCorp |
Product: Consul Status : PUBLISHED
CVE-2022-3920 Description
HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering\'s imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.
Metrics
CVSS Version: 3.1 |
Base Score: 5.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N