Vulnerabilities > Hashicorp > Consul > 1.8.0

DATE CVE VULNERABILITY TITLE RISK
2021-04-20 CVE-2021-28156 Unspecified vulnerability in Hashicorp Consul
HashiCorp Consul Enterprise version 1.8.0 up to 1.9.4 audit log can be bypassed by specifically crafted HTTP events.
network
low complexity
hashicorp
7.5
2021-01-11 CVE-2021-3121 Improper Validation of Array Index vulnerability in multiple products
An issue was discovered in GoGo Protobuf before 1.3.2.
network
low complexity
golang hashicorp CWE-129
8.6
2020-11-23 CVE-2020-28053 Incorrect Authorization vulnerability in Hashicorp Consul
HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read the Connect CA private key configuration.
network
low complexity
hashicorp CWE-863
6.5
2020-11-04 CVE-2020-25201 Unspecified vulnerability in Hashicorp Consul
HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes.
network
low complexity
hashicorp
7.5