漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Uncontrolled resource consumption in the Consul Connect authorization endpoint
Vulnerability Description
Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow the agent's intention-match cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-190124, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
HashiCorp Consul 资源管理错误漏洞
Vulnerability Description
HashiCorp Consul是美国HashiCorp公司的一款服务发现与配置管理中间件。 HashiCorp Consul 1.17.0版本至2.0.2版本存在资源管理错误漏洞,该漏洞源于Connect授权端点存在不受控制的资源消耗问题,可能导致调用者无限制地增长代理的意图匹配缓存,从而使操作员的缓存禁用配置失效。
CVSS Information
N/A
Vulnerability Type
N/A