Loading HuntDB...

GHSA-gw2g-hhc9-wgjh

GitHub Security Advisory

Missing Authorization in HashiCorp Consul

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.

Affected Packages

Go github.com/hashicorp/consul
Affected versions: 1.13.0 (fixed in 1.14.0)

Related CVEs

Key Information

GHSA ID
GHSA-gw2g-hhc9-wgjh
Published
November 16, 2022 12:00 PM
Last Modified
November 21, 2022 11:53 PM
CVSS Score
7.5 /10
Primary Ecosystem
Go
Primary Package
github.com/hashicorp/consul
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 6, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.