CVE-2020-25864
HashiCorp Consul Cross-site Scripting vulnerability
Record summary
CVE-2020-25864 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scripting. Fixed in 1.9.5, 1.8.10 and 1.7.14.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
github.com/hashicorp/consulBrowse Go / github.com/hashicorp/consul | GitHub Advisory | 1.9.0 to < 1.9.5 · Fixed in 1.9.5 | affected |
| 1.8.0 to < 1.8.10 · Fixed in 1.8.10 | affected | ||
| Before 1.7.14 · Fixed in 1.7.14 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMHashiCorp Consul/Consul Enterprise <=1.9.4 - Cross-Site ScriptingCVSS 6.1
HashiCorp Consul and Consul Enterprise up to version 1.9.4 are vulnerable to cross-site scripting via the key-value (KV) raw mode.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential data theft, session hijacking, or defacement of the affected Consul/Consul Enterprise application.
Remediation
Fixed in 1.9.5, 1.8.10 and 1.7.14.
Source: ProjectDiscovery