Description
HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if verify_server_hostname were set to false, even when it is actually set to true. This is fixed in 1.4.4.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4910 | HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the product behaves as if verify_server_hostname were set to false, even when it is actually set to true. This is fixed in 1.4.4. |
Github GHSA |
GHSA-q7fx-wm2p-qfj8 | HashiCorp Consul vulnerable to Origin Validation Error |
References
| Link | Providers |
|---|---|
| https://github.com/hashicorp/consul/issues/5519 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:01:54.083Z
Reserved: 2019-03-14T00:00:00.000Z
Link: CVE-2019-9764
No data.
Status : Modified
Published: 2019-03-26T14:29:00.507
Modified: 2024-11-21T04:52:16.080
Link: CVE-2019-9764
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA