漏洞描述
HashiCorp Consul and Consul Enterprise up to version 1.9.4 are vulnerable to cross-site scripting via the key-value (KV) raw mode.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
discuss.hashicorp.comhttps://discuss.hashicorp.com/t/hcsec-2021-07-consul-api-kv-endpoint-vulnerable-to-cross-site-scripting/23368↗www.hashicorp.comhttps://www.hashicorp.com/blog/category/consul↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2020-25864↗security.gentoo.orghttps://security.gentoo.org/glsa/202208-09↗github.comhttps://github.com/ARPSyndicate/cvemon↗