CVE-2020-13250

high

Description

HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to denial of service. Fixed in 1.6.6 and 1.7.4.

References

https://github.com/hashicorp/consul/pull/8023

https://github.com/hashicorp/consul/blob/v1.7.4/CHANGELOG.md

https://github.com/hashicorp/consul/blob/v1.6.6/CHANGELOG.md

Details

Source: Mitre, NVD

Published: 2020-06-11

Updated: 2021-07-21

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High