Skip to content

Version update to resolve security issue in github.com/hashicorp/consul#5776

Closed
MitaliBo wants to merge 1 commit intovitessio:masterfrom
MitaliBo:master
Closed

Version update to resolve security issue in github.com/hashicorp/consul#5776
MitaliBo wants to merge 1 commit intovitessio:masterfrom
MitaliBo:master

Conversation

@MitaliBo
Copy link
Copy Markdown

github.com/hashicorp/consul is vulnerable so suggesting to upgrade the version to a secured one. You can check module vulnerability here :


https://search.gocenter.io/github.com~2Fhashicorp~2Fconsul/info?version=v1.4.0

CVE-2019-12291
HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy even with default deny settings configured.

CVE-2018-19653
HashiCorp Consul 0.5.1 through 1.4.0 can use cleartext agent-to-agent RPC communication because the verify_outgoing setting is improperly documented. NOTE: the vendor has provided reconfiguration steps that do not require a software upgrade.

@MitaliBo MitaliBo requested a review from sougou as a code owner January 30, 2020 22:13
@deepthi deepthi requested review from morgo and rafael January 30, 2020 22:38
@deepthi
Copy link
Copy Markdown
Collaborator

deepthi commented Jan 31, 2020

welcome @MitaliBo! thank you for the contribution.
Can you please fix the DCO so that we can accept this PR?

@deepthi deepthi added the dependencies Pull requests that update a dependency file label Jan 31, 2020
@deepthi
Copy link
Copy Markdown
Collaborator

deepthi commented Jan 31, 2020

@morgo can you evaluate this for inclusion in 5.0?

@morgo
Copy link
Copy Markdown
Contributor

morgo commented Feb 1, 2020

@morgo can you evaluate this for inclusion in 5.0?

Yes, I would like to. @MitaliBo can you please resolve the DCO? (git commit -s --amend + git push -f should do it.)

morgo added a commit that referenced this pull request Feb 3, 2020
Signed-off-by: Morgan Tocker <tocker@gmail.com>
@morgo morgo mentioned this pull request Feb 19, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants