VYPR
Medium severity6.5NVD Advisory· Published Feb 24, 2022· Updated Jun 17, 2026

CVE-2022-24687

CVE-2022-24687

Description

HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gateway allow a user with service:write to register a specifically-defined service that can cause Consul servers to panic. Fixed in 1.9.15, 1.10.8, and 1.11.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/hashicorp/consulGo
>= 1.8.0, < 1.9.151.9.15
github.com/hashicorp/consulGo
>= 1.10.0, < 1.10.81.10.8
github.com/hashicorp/consulGo
>= 1.11.0, < 1.11.31.11.3

Affected products

5
  • Hashicorp/Consul3 versions
    cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*+ 2 more
    • cpe:2.3:a:hashicorp:consul:*:*:*:*:-:*:*:*range: >=1.8.0,<1.9.15
    • cpe:2.3:a:hashicorp:consul:*:*:*:*:enterprise:*:*:*range: >=1.8.0,<1.9.15
    • (no CPE)
  • osv-coords2 versions
    >= 1.8.0, < 1.9.15+ 1 more
    • (no CPE)range: >= 1.8.0, < 1.9.15
    • (no CPE)range: >= 1.8.0, < 1.9.15

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.