AIKIDO-2024-10339

github.com/hashicorp/consul is vulnerable to Cross-site Scripting (XSS)

24

Low

github.com/hashicorp/consul go

AIKIDO-2024-10339: github.com/hashicorp/consul is vulnerable to Cross-site Scripting (XSS) in versions 1.9.0 - 1.19.2.

Cross-site Scripting (XSS)
Vuln in 1.9.0 - 1.19.2
Fixed in 1.20.0
No CVE available
TL;DR

Affected versions of the package are vulnerable to Cross-site Scripting (XSS) when opening a tab based on user defined input.

Who does this affect?

You're affected if you are using a version which is within vulnerability ranges.

How can it be fixed?

Upgrade github.com/hashicorp/consul library to patch version.

Background info

Link to vendor website

Logo
© 2024 Aikido Security BV | BE0792914919
🇪🇺 Grauwpoort 1, 9000 Ghent, Belgium
🇺🇸 95 Third St, 2nd Fl, San Francisco, CA 94103, US