CVE-2022-3920High· 7.5▾ TwilightMissing Authorization in HashiCorp Consul
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
0.7% → 0.7%
HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0.
github.com/hashicorp/consul >= 1.13.0, < 1.14.0Upgrade to a patched release:
github.com/hashicorp/consul 1.14.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-11374Medium· 6.5Consul key/value endpoint is vulnerable to denial of service
CVE-2021-38698Medium· 6.5HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access…
CVE-2018-19653Medium· 5.9HashiCorp Consul can use cleartext agent-to-agent RPC communication
CVE-2020-7219High· 7.5Denial of Service (DoS) in HashiCorp Consul
CVE-2021-32574High· 7.5Hashicorp Consul Missing SSL Certificate Validation
CVE-2023-0845Medium· 6.5Consul Server Panic when Ingress and API Gateways Configured with Peering Connections