Skip to content

Conversation

@HenriqueOCabral
Copy link
Member

No description provided.

Copy link
Collaborator

@kapyteinaikido kapyteinaikido left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changelog also mentions two other vulnerabilities (which we should maybe cover in separate advisories).

agent: Fix a security vulnerability to filter out anonymous tokens along with empty tokens when setting the Results-Filtered-By-ACLs header [https://github.com/hashicorp/consul/issues/22534]

agent: Fix a security vulnerability where the attacker could read agent’s TLS certificate and private key by using the group ID that the Consul agent runs as. [https://github.com/hashicorp/consul/issues/22626]

Is there an existing (GitHub) security advisory for those?

@HenriqueOCabral
Copy link
Member Author

The changelog also mentions two other vulnerabilities (which we should maybe cover in separate advisories).

agent: Fix a security vulnerability to filter out anonymous tokens along with empty tokens when setting the Results-Filtered-By-ACLs header [https://github.com/hashicorp/consul/issues/22534]

agent: Fix a security vulnerability where the attacker could read agent’s TLS certificate and private key by using the group ID that the Consul agent runs as. [https://github.com/hashicorp/consul/issues/22626]

Is there an existing (GitHub) security advisory for those?

That was a good catch, I was rushing through many repos and didn't notice the first one was affecting not only unit test code and the other one might be good to document the mitigation so many folks could fix it even without patching the lib. I'll create them :)

@HenriqueOCabral
Copy link
Member Author

#866

#867

@kapyteinaikido

@kapyteinaikido kapyteinaikido merged commit 51027ba into main Oct 6, 2025
1 check passed
@kapyteinaikido kapyteinaikido deleted the new-vuln-timming-attacks-consul branch October 6, 2025 14:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants