2021-07-16 10:22:41 +08:00

425 B

Consul Service API RCE

Under a specific configuration, a malicious attacker can remotely execute commands on the Consul server without authorization by sending a carefully constructed HTTP request.

FOFA query rule: title="Consul by HashiCorp" || protocol="consul(http)"

Demo