CVE-2020-25864

MEDIUM NUCLEI

Hashicorp Consul < 1.7.14 - XSS

Title source: rule

Description

HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scripting. Fixed in 1.9.5, 1.8.10 and 1.7.14.

Nuclei Templates (1)

HashiCorp Consul/Consul Enterprise <=1.9.4 - Cross-Site Scripting
MEDIUMby c-sh0
Shodan: http.title:"consul by hashicorp" || cpe:"cpe:2.3:a:hashicorp:consul"
FOFA: title="consul by hashicorp"

Scores

CVSS v3 6.1
EPSS 0.8334
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
hashicorp/consul < 1.7.14 (2 CPE variants)
hashicorp/consul 1.9.0 - 1.9.5Go
Published Apr 20, 2021
Tracked Since Feb 18, 2026