Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 872086 - <app-admin/consul-1.12.5: multiple vulnerabilities
Summary: <app-admin/consul-1.12.5: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://github.com/hashicorp/consul/r...
Whiteboard: B4 [noglsa]
Keywords:
Depends on: 872197
Blocks:
  Show dependency tree
 
Reported: 2022-09-20 20:31 UTC by John Helmert III
Modified: 2022-09-21 14:37 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-09-20 20:31:23 UTC
From URL,

"auto-config: Added input validation for auto-config JWT authorization checks. Prior to this change, it was possible for malicious actors to construct requests which incorrectly pass custom JWT claim validation for the AutoConfig.InitialConfiguration endpoint. Now, only a subset of characters are allowed for the input before evaluating the bexpr. [GH-14577]

connect: Added URI length checks to ConnectCA CSR requests. Prior to this change, it was possible for a malicious actor to designate multiple SAN URI values in a call to the ConnectCA.Sign endpoint. The endpoint now only allows for exactly one SAN URI to be specified. [GH-14579]"

Please bump to 1.12.5. I suppose more releases are coming though, presumably
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-09-20 21:36:43 UTC
1.11.9 released with the same fixes
Comment 2 Larry the Git Cow gentoo-dev 2022-09-21 00:32:40 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=09a02fbc62b628b2d770269609bdfbabaf2fc072

commit 09a02fbc62b628b2d770269609bdfbabaf2fc072
Author:     Zac Medico <zmedico@gentoo.org>
AuthorDate: 2022-09-21 00:31:24 +0000
Commit:     Zac Medico <zmedico@gentoo.org>
CommitDate: 2022-09-21 00:32:35 +0000

    app-admin/consul: add 1.13.2
    
    Bug: https://bugs.gentoo.org/872086
    Signed-off-by: Zac Medico <zmedico@gentoo.org>

 app-admin/consul/Manifest             |  2 ++
 app-admin/consul/consul-1.13.2.ebuild | 56 +++++++++++++++++++++++++++++++++++
 2 files changed, 58 insertions(+)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e25044588d42f54e73c31ba69db9570f8fc3f4c3

commit e25044588d42f54e73c31ba69db9570f8fc3f4c3
Author:     Zac Medico <zmedico@gentoo.org>
AuthorDate: 2022-09-21 00:06:44 +0000
Commit:     Zac Medico <zmedico@gentoo.org>
CommitDate: 2022-09-21 00:32:35 +0000

    app-admin/consul: add 1.12.5
    
    Bug: https://bugs.gentoo.org/872086
    Signed-off-by: Zac Medico <zmedico@gentoo.org>

 app-admin/consul/Manifest             |  2 ++
 app-admin/consul/consul-1.12.5.ebuild | 51 +++++++++++++++++++++++++++++++++++
 2 files changed, 53 insertions(+)
Comment 3 Larry the Git Cow gentoo-dev 2022-09-21 00:35:28 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b7aec9a8f7b6a672503ce305af7d0e3c3578cf50

commit b7aec9a8f7b6a672503ce305af7d0e3c3578cf50
Author:     Zac Medico <zmedico@gentoo.org>
AuthorDate: 2022-09-21 00:33:48 +0000
Commit:     Zac Medico <zmedico@gentoo.org>
CommitDate: 2022-09-21 00:34:08 +0000

    app-admin/consul: drop 1.12.4, 1.13.1
    
    Bug: https://bugs.gentoo.org/872086
    Signed-off-by: Zac Medico <zmedico@gentoo.org>

 app-admin/consul/Manifest             |  4 ---
 app-admin/consul/consul-1.12.4.ebuild | 51 -------------------------------
 app-admin/consul/consul-1.13.1.ebuild | 56 -----------------------------------
 3 files changed, 111 deletions(-)
Comment 4 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-09-21 01:32:01 UTC
What of 1.9.x?
Comment 5 Larry the Git Cow gentoo-dev 2022-09-21 12:57:51 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=b85fd58a10f811f1152c29f69c522bc58098f390

commit b85fd58a10f811f1152c29f69c522bc58098f390
Author:     Zac Medico <zmedico@gentoo.org>
AuthorDate: 2022-09-21 12:57:21 +0000
Commit:     Zac Medico <zmedico@gentoo.org>
CommitDate: 2022-09-21 12:57:27 +0000

    app-admin/consul: drop 1.9.17
    
    Bug: https://bugs.gentoo.org/872086
    Signed-off-by: Zac Medico <zmedico@gentoo.org>

 app-admin/consul/Manifest             |  2 --
 app-admin/consul/consul-1.9.17.ebuild | 56 -----------------------------------
 2 files changed, 58 deletions(-)
Comment 6 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-09-21 14:37:08 UTC
Thanks! No CVEs so I guess Hashicorp doesn't think these issues are important enough. No GLSA.