Description
HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2."
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:HExploitability: 2.8 | Impact: 4.2Attack Vector: Network
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: None
Availability: High
Affected Packages3 packages
🔴Vulnerability Details
4OSVImproper handling of node names in JWT claims assertions in github.com/hashicorp/consul↗2024-04-05 ▶ OSVHashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions↗2022-09-25 ▶ GHSAHashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions↗2022-09-25 ▶ OSVCVE-2021-41803: HashiCorp Consul 1↗2022-09-23 ▶ 📋Vendor Advisories
2Red Hatconsul: Consul Auto-Config JWT Authorization Missing Input Validation↗2022-09-23 ▶ DebianCVE-2021-41803: consul - HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate...↗2021 ▶