Skip to content

Bump consul to 1.11.3 due to CVE-2022-24687 #4682

@sergiodj

Description

@sergiodj

Ref.: https://www.cve.org/CVERecord?id=CVE-2022-24687

I'm not entirely sure whether cortex uses consul's Ingress Gateway feature, but I found several uses of IngressGateway inside the github.com/hashicorp/consul/api module, so I think it's a good idea to bump consul to 1.11.3 in order to mitigate the CVE.

Thanks.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions