Hashicorp Consul API Unauthenticated
In HashiCorp Consul's API without authentication arises when Consul is improperly secured, exposing its endpoints to unauthorized access.
共找到 5 条公开漏洞记录
In HashiCorp Consul's API without authentication arises when Consul is improperly secured, exposing its endpoints to unauthorized access.
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11 are susceptible to server-side request forgery. When redirects are returned by HTTP health check endpoints, Consul follows these HTTP redirects by default. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
HashiCorp Consul and Consul Enterprise up to version 1.9.4 are vulnerable to cross-site scripting via the key-value (KV) raw mode.
Hashicorp Consul Services API is vulnerable to an attack that can be leveraged to perform remote command execution on Consul nodes.