Intel

AIKIDO-2024-10408

github.com/hashicorp/consul is vulnerable to Path Traversal

Path TraversalCVE-2024-10005 Published Nov 4, 2024

83

High Risk

This Affects:

gogithub.com/hashicorp/consul
0.1.0 - 1.20.0
Fixed in 1.20.1
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to path traversal. Malicious actors can exploit URL paths in Layer 7 (L7) traffic intentions to bypass HTTP request path-based access controls, potentially gaining unauthorized access to restricted files or resources.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/hashicorp/consul is vulnerable to Path Traversal in versions 0.1.0 - 1.20.0.

How to fix this

Upgrade the github.com/hashicorp/consul library to the patch version.