GobyVuls/Consul/Consul_Service_API_RCE
2021-07-16 10:22:41 +08:00
..
2021-07-16 10:22:41 +08:00

Consul Service API RCE

Under a specific configuration, a malicious attacker can remotely execute commands on the Consul server without authorization by sending a carefully constructed HTTP request.

FOFA query rule: title="Consul by HashiCorp" || protocol="consul(http)"

Demo