VDB
CVE-2022-29153
CVE-2022-29153
PUBLISHED
KEV
CVSS 7.5 HIGH
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.
EPSS 8.68% · 94.9th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
8.68%
94.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | consul | 1.11.0, 0, 1.10.0 |
| Bitnami | consul | 0, 1.10.0, 1.11.0 |
Timeline
- Apr 19, 2022 CVE Published
- Apr 19, 2022 PoC Published
- Apr 20, 2022 EPSS Score
- Feb 23, 2023 CVE Updated
- Apr 26, 2023 EPSS Score
- Sep 17, 2023 EPSS Score
- Nov 13, 2023 VulnCheck KEV Exploitation
- Jan 7, 2024 EPSS Score
- Jan 22, 2024 VulnCheck KEV Exploitation
- Jan 24, 2024 VulnCheck KEV Exploitation
- Jan 27, 2024 VulnCheck KEV Exploitation
- Jan 28, 2024 VulnCheck KEV Exploitation
References
- Nuclei Template exploit
- Multiples vulnérabilités dans les produits IBM advisory
- https://discuss.hashicorp.com advisory
- https://discuss.hashicorp.com/t/hcsec-2022-10-consul-s-http-health-check-may-allow-server-side-request-forgery/ advisory
- https://discuss.hashicorp.com/t/hcsec-2022-10-consul-s-http-health-check-may-allow-server-side-request-forgery/38393 advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RBODKZL7HQE5XXS3SA2VIDVL4LAA5RWH/ advisory
- https://security.gentoo.org/glsa/202208-09 advisory
- https://security.netapp.com/advisory/ntap-20220602-0005/ advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-29153 url