CVE-2020-13250

HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to denial of service. Fixed in 1.6.6 and 1.7.4.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
hashicorpconsul
1.2.0 ≤
𝑥
< 1.6.6
hashicorpconsul
1.2.0 ≤
𝑥
< 1.6.6
hashicorpconsul
1.7.0 ≤
𝑥
< 1.7.4
hashicorpconsul
1.7.0 ≤
𝑥
< 1.7.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
consul
bullseye
1.8.7+dfsg1-2
fixed
buster
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
consul
noble
dne
mantic
not-affected
lunar
dne
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
needed
eoan
not-affected
bionic
not-affected
xenial
dne
trusty
dne