CVE-2020-13250Allocation of Resources Without Limits or Throttling in Hashicorp Consul

Severity
7.5HIGHNVD
EPSS
0.9%
top 24.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateAug 21

Description

HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to denial of service. Fixed in 1.6.6 and 1.7.4.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDhashicorp/consul1.2.01.6.6+1
Gogithub.com/hashicorp_consul1.2.01.6.6+1
Debianhashicorp/consul< 1.7.4+dfsg1-1
debiandebian/consul< consul 1.7.4+dfsg1-1 (bullseye)

Patches

🔴Vulnerability Details

4
OSV
Allocation of Resources Without Limits or Throttling in Hashicorp Consul in github.com/hashicorp/consul2024-08-21
GHSA
Allocation of Resources Without Limits or Throttling in Hashicorp Consul2021-05-18
OSV
Allocation of Resources Without Limits or Throttling in Hashicorp Consul2021-05-18
OSV
CVE-2020-13250: HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 12020-06-11

📋Vendor Advisories

1
Debian
CVE-2020-13250: consul - HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0)...2020