Consul Peering Imported Nodes/Services Leak
CVE-2022-3920
5.3MEDIUM
What is CVE-2022-3920?
HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.
Affected Version(s)
Consul 64 bit 1.13.0
Consul 64 bit 1.13.1
Consul 64 bit 1.13.2