Vulnerabilities > Hashicorp > Consul > 1.15.0

DATE CVE VULNERABILITY TITLE RISK
2024-10-30 CVE-2024-10005 Path Traversal vulnerability in Hashicorp Consul
A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules.
network
low complexity
hashicorp CWE-22
5.8
2024-10-30 CVE-2024-10006 Improper Encoding or Escaping of Output vulnerability in Hashicorp Consul
A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.
network
low complexity
hashicorp CWE-116
5.8
2024-10-30 CVE-2024-10086 Cross-site Scripting vulnerability in Hashicorp Consul
A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and lead to reflected XSS.
network
low complexity
hashicorp CWE-79
6.1
2023-06-02 CVE-2023-1297 Unspecified vulnerability in Hashicorp Consul
Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial of service.
network
low complexity
hashicorp
7.5
2023-06-02 CVE-2023-2816 Unspecified vulnerability in Hashicorp Consul 1.15.0
Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.
network
low complexity
hashicorp
6.5