CVE-2019-9764
HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if verify_server_hostname were set to false, even when it is actually set to true. This is fixed in 1.4.4.
Published
2019-03-26T14:29:00.507
Last Modified
2024-11-21T04:52:16.080
Status
Modified
Source
[email protected]
Severity
CVSSv3.0: 7.4 (HIGH)
CVSSv2 Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
- Access Vector: NETWORK
- Access Complexity: MEDIUM
- Authentication: NONE
- Confidentiality Impact: PARTIAL
- Integrity Impact: PARTIAL
- Availability Impact: NONE
Exploitability Score
8.6
Impact Score
4.9
Weaknesses
Affected Vendors & Products
Type |
Vendor |
Product |
Version/Range |
Vulnerable? |
Application |
hashicorp
|
consul
|
1.4.3 |
Yes
|
References