CVE-2022-29153 in HashiCorp and Fedora Project Products
Published on April 19, 2022
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.
Products Associated with CVE-2022-29153
stack.watch emails you whenever new vulnerabilities are published in HashiCorp Consul or Fedora Project Fedora. Just hit a watch button to start following.
Exploit Probability
EPSS
87.42%
Percentile
99.45%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.