vendor:
Consul
by:
GatoGamer1155, 0bfxgh0st
9.8
CVSS
CRITICAL
Remote Command Execution (RCE)
78
CWE
Product Name: Consul
Affected Version From: v1.0
Affected Version To: v1.0
Patch Exists: NO
Related CWE:
CPE: a:hashicorp:consul:1.0
Platforms Tested: Ubuntu Server
2022
Hashicorp Consul v1.0 – Remote Command Execution (RCE)
Exploit for gain reverse shell on Remote Command Execution via API
Mitigation:
Ensure that the Consul API is not exposed to the public internet and that authentication is enabled for the API.