Vulnerabilities > Hashicorp > Consul > 1.12.0

DATE CVE VULNERABILITY TITLE RISK
2023-03-09 CVE-2023-0845 NULL Pointer Dereference vulnerability in Hashicorp Consul
Consul and Consul Enterprise allowed an authenticated user with service:write permissions to trigger a workflow that causes Consul server and client agents to crash under certain circumstances.
network
low complexity
hashicorp CWE-476
6.5
2022-09-23 CVE-2022-40716 Unchecked Return Value vulnerability in Hashicorp Consul
HashiCorp Consul and Consul Enterprise up to 1.11.8, 1.12.4, and 1.13.1 do not check for multiple SAN URI values in a CSR on the internal RPC endpoint, enabling leverage of privileged access to bypass service mesh intentions.
network
low complexity
hashicorp CWE-252
6.5