Consul RCE 漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Protecting Consul from RCE Risk in Specific Configurations `NOV 27 2018 THE CONSUL TEAM` **Introduction** We’ve recently become aware of a set of malware targeting Consul nodes with a specific configuration which allows remote code execution. Members of our community also (responsibly) reported incidents caused by this malware, and worked with us to include a patch in a recent version of Consul that protects from this threat in the wild. This post details how this malware may affect users, depending on their configuration, as well as outlines the steps we've taken to backport a patch for versions 1.2.4, 1.1.1, 1.0.8, and 0.9.4 to make it easy for older versions of Consul to be secured without a major version upgrade. **Summary** You should take action if you have -enable-script-checks set to true, or are running Consul 0.9.0 or earlier, and the Consul API is available on an interface that can be accessed over the network. Steps to remediate: * 1.Upgrade to one of the versions...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息