CVE-2022-29153 PUBLISHED

HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.

EPSS 87.76% · 99.5th percentile

Risk Scores

EPSS Score
87.76%
99.5th percentile

Affected Products

VendorProductVersions
Bitnamiconsul0, 1.10.0, 1.11.0
Bitnamiconsul0, 1.10.0, 1.11.0

Timeline

References

Open in Interactive Console →