CVE-2021-38698 — Missing Authorization in Hashicorp Consul
Severity
6.5MEDIUMNVD
EPSS
0.6%
top 31.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 7
Latest updateAug 21
Description
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages3 packages
🔴Vulnerability Details
4OSV▶
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. in github.com/hashicorp/consul↗2024-08-21
OSV▶
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic.↗2021-09-08
GHSA▶
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic.↗2021-09-08
📋Vendor Advisories
1Debian▶
CVE-2021-38698: consul - HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed service...↗2021