CVE-2020-25864 - log back

CVE-2020-25864 edited at 20 Apr 2021 14:52:27
Description
- A vulnerability was identified in Consul and Consul Enterprise ("Consul") before version 1.9.5 where a specially crafted KV entry could be used to perform a cross-site scripting (XSS) attack when viewed in the raw mode.
+ A vulnerability was identified in Consul and Consul Enterprise ("Consul") up to version 1.9.4 where a specially crafted KV entry could be used to perform a cross-site scripting (XSS) attack when viewed in the raw mode. The issue is fixed in versions 1.9.5, 1.8.10 and 1.7.14.
References
+ https://discuss.hashicorp.com/t/hcsec-2021-07-consul-api-kv-endpoint-vulnerable-to-cross-site-scripting/23368
https://github.com/hashicorp/consul/pull/10023
https://github.com/hashicorp/consul/commit/dc937c953279bd40645d8ad020f41c6bf93df459
CVE-2020-25864 edited at 16 Apr 2021 11:11:21
Description
- A vulnerability was identified in Consul and Consul Enterprise ("Consul") such that a specially crafted KV entry could be used to perform a cross-site scripting (XSS) attack when viewed in the raw mode.
+ A vulnerability was identified in Consul and Consul Enterprise ("Consul") before version 1.9.5 where a specially crafted KV entry could be used to perform a cross-site scripting (XSS) attack when viewed in the raw mode.
CVE-2020-25864 edited at 16 Apr 2021 11:09:01
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Cross-site scripting
Description
+ A vulnerability was identified in Consul and Consul Enterprise ("Consul") such that a specially crafted KV entry could be used to perform a cross-site scripting (XSS) attack when viewed in the raw mode.
References
+ https://github.com/hashicorp/consul/pull/10023
+ https://github.com/hashicorp/consul/commit/dc937c953279bd40645d8ad020f41c6bf93df459
Notes
CVE-2020-25864 created at 16 Apr 2021 11:07:03