CVE-2020-13250

EUVD-2021-1185
HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to denial of service. Fixed in 1.6.6 and 1.7.4.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
Affected Products (NVD)
VendorProductVersion
hashicorpconsul
1.2.0 ≤
𝑥
< 1.6.6
hashicorpconsul
1.2.0 ≤
𝑥
< 1.6.6
hashicorpconsul
1.7.0 ≤
𝑥
< 1.7.4
hashicorpconsul
1.7.0 ≤
𝑥
< 1.7.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
consul
bullseye
1.8.7+dfsg1-2
fixed
buster
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
consul
bionic
not-affected
eoan
not-affected
focal
needed
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
not-affected
kinetic
not-affected
lunar
dne
mantic
not-affected
noble
dne
trusty
dne
xenial
dne