From f7375fcfd657cfc3887863e562d7feab296947e9 Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Wed, 10 Aug 2022 04:07:00 +0000 Subject: [ GLSA 202208-09 ] HashiCorp Consul: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/760696 Bug: https://bugs.gentoo.org/783483 Bug: https://bugs.gentoo.org/802522 Bug: https://bugs.gentoo.org/812497 Bug: https://bugs.gentoo.org/834006 Bug: https://bugs.gentoo.org/838328 Signed-off-by: GLSAMaker Signed-off-by: John Helmert III --- glsa-202208-09.xml | 55 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 55 insertions(+) create mode 100644 glsa-202208-09.xml diff --git a/glsa-202208-09.xml b/glsa-202208-09.xml new file mode 100644 index 0000000..e692833 --- /dev/null +++ b/glsa-202208-09.xml @@ -0,0 +1,55 @@ + + + + HashiCorp Consul: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in HashiCorp Consul, the worst of which could result in denial of service. + consul + 2022-08-10 + 2022-08-10 + 760696 + 783483 + 802522 + 812497 + 834006 + 838328 + remote + + + 1.9.17 + 1.9.17 + + + +

HashiCorp Consul is a tool for service discovery, monitoring and configuration.

+
+ +

Multiple vulnerabilities have been discovered in HashiCorp Consul. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All HashiCorp Consul users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-admin/consul-1.9.17" + +
+ + CVE-2020-25201 + CVE-2020-25864 + CVE-2020-28053 + CVE-2021-28156 + CVE-2021-32574 + CVE-2021-36213 + CVE-2021-38698 + CVE-2022-24687 + CVE-2022-29153 + + ajak + ajak +
\ No newline at end of file -- cgit v1.2.3-18-g5258