← back
CVE-2022-29153observed exploitation

CVE-2022-29153

40Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 8.7%
from disclosure to weapon
Published on NVDApr 19
VulnCheck+573d
exploitation probability
8.7%top 5% of all CVEs
observed exploitation
yesVulnCheck
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.
Affected products
n/a · n/a