CVE-2020-13250

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-13250
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13250.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-13250
Aliases
Downstream
Published
2020-06-11T20:15:11Z
Modified
2025-10-21T05:22:23.130189Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to denial of service. Fixed in 1.6.6 and 1.7.4.

References

Affected packages

Git / github.com/hashicorp/consul

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/consul
Events

Affected versions

api/v1.*

api/v1.0.0
api/v1.0.1
api/v1.1.0
api/v1.2.0

internal/v0.*

internal/v0.1.0

sdk/v0.*

sdk/v0.1.0
sdk/v0.1.1
sdk/v0.2.0
sdk/v0.3.0

v1.*

v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.4.0
v1.4.0-rc1
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.0-beta1
v1.6.0-beta2
v1.6.0-beta3
v1.6.0-rc1
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5