VDB
BDU%3A2024-10200
BDU%3A2024-10200
PUBLISHED
CVSS 6.099999904632568 MEDIUM
Уязвимость инструмента настройки сервиса Consul, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)
Risk Scores
CVSS 3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, ООО «Ред Софт», Red Hat Inc., HashiCorp | Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Red Hat OpenShift Dev Spaces, Consul Enterprise, Consul Community Edition | |
| HashiCorp | Consul | 1.4.1 |
| HashiCorp | Consul Enterprise | 1.4.1 |
Timeline
- Oct 30, 2024 CVE Published
- Oct 31, 2024 PoC Published
- Nov 25, 2024 CVE Updated
- Jan 10, 2025 PoC Published
References
- https://security-tracker.debian.org/tracker/CVE-2024-10086 url
- https://discuss.hashicorp.com/t/hcsec-2024-24-consul-vulnerable-to-reflected-xss-on-content-type-error-manipulation/71037 advisory
- https://discuss.hashicorp.com/t/hcsec-2024-24-consul-vulnerable-to-reflected-xss-on-content-type-error-manipulation url
- https://security.netapp.com/advisory/ntap-20250110-0006/ url
- https://redos.red-soft.ru/support/secure/ url
- https://access.redhat.com/security/cve/CVE-2024-10086 advisory
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory