Server-Side Request Forgery (SSRF) in Consul Enterprise and Consul - CVE-2022-29153
Published: June 5, 2023
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
Affected software
Consul
Gentoo Linux
Fedora
IBM Edge Application Manager
golang-github-hashicorp-consul-sdk
golang-github-containerd-cgroups
containerd
app-admin/consul
golang-github-hashicorp-consul-api
moby-engine
IBM Cloud Pak for Watson AIOps
Robotic Process Automation for Cloud Pak
How to mitigate CVE-2022-29153
Consul - addressed in versions 1.9.17, 1.10.10, 1.11.5
golang-github-hashicorp-consul-sdk - addressed in versions 0.13.0-1.fc36, 0.13.0-1.fc37
golang-github-containerd-cgroups - addressed in versions 1.0.4-3.fc36, 1.0.4-3.fc37
containerd - addressed in versions 1.6.14-2.fc36, 1.6.14-2.fc37
app-admin/consul - update to 1.9.17
golang-github-hashicorp-consul-api - addressed in versions 1.18.0-1.fc36, 1.18.0-1.fc37
IBM Cloud Pak for Watson AIOps - update to 4.1
moby-engine - addressed in versions 20.10.21-1.fc36, 20.10.21-1.fc37, 20.10.22-1.fc37
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.18
External References
- https://discuss.hashicorp.com
- https://discuss.hashicorp.com/t/hcsec-2022-10-consul-s-http-health-check-may-allow-server-side-request-forgery/38393
- https://security.netapp.com/advisory/ntap-20220602-0005/
- https://security.gentoo.org/glsa/202208-09
- https://discuss.hashicorp.com/t/hcsec-2022-10-consul-s-http-health-check-may-allow-server-side-request-forgery/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RBODKZL7HQE5XXS3SA2VIDVL4LAA5RWH/
Related Security Bulletins
- Multiple vulnerabilities in IBM Edge Application Manager
- Fedora 37 update for moby-engine
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- IBM Robotic Process Automation for Cloud Pak update for HashiCorp Consul
- Gentoo update for HashiCorp Consul
- Fedora 37 update for containerd, golang-github-containerd-cgroups, moby-engine
- Fedora 36 update for containerd, golang-github-containerd-cgroups, moby-engine
- Fedora 36 update for golang-github-hashicorp-consul-sdk
- Fedora 37 update for golang-github-hashicorp-consul-sdk
- Fedora 37 update for golang-github-hashicorp-consul-api
- Fedora 36 update for golang-github-hashicorp-consul-api