Server-Side Request Forgery (SSRF) in Consul Enterprise and Consul - CVE-2022-29153

 

Server-Side Request Forgery (SSRF) in Consul Enterprise and Consul - CVE-2022-29153

Published: June 5, 2023


Vulnerability identifier: #VU76839
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29153
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


Affected software

Consul Enterprise
Consul
Gentoo Linux
Fedora
IBM Edge Application Manager
golang-github-hashicorp-consul-sdk
golang-github-containerd-cgroups
containerd
app-admin/consul
golang-github-hashicorp-consul-api
moby-engine
IBM Cloud Pak for Watson AIOps
Robotic Process Automation for Cloud Pak

How to mitigate CVE-2022-29153

Install updates from vendor's website.

Consul Enterprise - addressed in versions 1.9.17, 1.10.10, 1.11.5
Consul - addressed in versions 1.9.17, 1.10.10, 1.11.5
golang-github-hashicorp-consul-sdk - addressed in versions 0.13.0-1.fc36, 0.13.0-1.fc37
golang-github-containerd-cgroups - addressed in versions 1.0.4-3.fc36, 1.0.4-3.fc37
containerd - addressed in versions 1.6.14-2.fc36, 1.6.14-2.fc37
app-admin/consul - update to 1.9.17
golang-github-hashicorp-consul-api - addressed in versions 1.18.0-1.fc36, 1.18.0-1.fc37
IBM Cloud Pak for Watson AIOps - update to 4.1
moby-engine - addressed in versions 20.10.21-1.fc36, 20.10.21-1.fc37, 20.10.22-1.fc37
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.18

External References

Related Security Bulletins