
Cloud Vulnerability DB
A community-led vulnerabilities database
HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to denial of service. The vulnerability was fixed in versions 1.6.6 and 1.7.4 (GitHub PR, Consul Changelog).
The vulnerability stems from the caching feature in both the HTTP API and DNS services lacking size limits on the cache. Without proper bounds on resource usage, the cache could grow unbounded, potentially leading to excessive memory consumption and denial of service conditions. The issue affects the caching functionality introduced in Consul v1.2.0 for HTTP API and v1.4.3 for DNS (GitHub PR).
The vulnerability could allow attackers to cause denial of service conditions through unbounded resource consumption in the cache, potentially affecting system availability and performance (GitHub PR).
The vulnerability can be exploited by making requests that populate the cache without limits, leading to potential memory exhaustion. No authentication is required to exploit this vulnerability (GitHub PR).
The recommended mitigation steps include: 1) Upgrading to Consul v1.7.4 or v1.6.6, 2) Disabling the DNS cache feature using dns_use_cache configuration option, 3) Disabling the HTTP cache feature using http_config.use_cache option (GitHub PR, Consul Changelog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."