PT-2021-11191 · Hashicorp+2 · Hashicorp Consul Enterprise+3

Published

2021-04-20

·

Updated

2024-08-20

·

CVE-2020-25864

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: HashiCorp Consul and Consul Enterprise versions prior to 1.9.5 HashiCorp Consul and Consul Enterprise versions prior to 1.8.10 HashiCorp Consul and Consul Enterprise versions prior to 1.7.14
Description: The issue concerns a cross-site scripting vulnerability in the key-value (KV) raw mode of HashiCorp Consul and Consul Enterprise.
Recommendations: For versions prior to 1.9.5, update to version 1.9.5 or later. For versions prior to 1.8.10, update to version 1.8.10 or later. For versions prior to 1.7.14, update to version 1.7.14 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3445
ALT-PU-2023-7106
ALT-PU-2024-8028
BIT-CONSUL-2020-25864
CVE-2020-25864
GHSA-8XMX-H8RQ-H94J
GO-2023-1851

Affected Products

Alt Linux
Astra Linux
Hashicorp Consul Enterprise
Hashicorp Consul