Vulnerabilities > Hashicorp > Consul > High

DATE CVE VULNERABILITY TITLE RISK
2023-12-04 CVE-2023-5332 Patch in third party library Consul requires 'enable-script-checks' to be set to False.
network
high complexity
gitlab hashicorp
8.1
2023-08-09 CVE-2023-3518 Unspecified vulnerability in Hashicorp Consul 1.16.0
HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities.
network
low complexity
hashicorp
7.3
2023-06-02 CVE-2023-1297 Unspecified vulnerability in Hashicorp Consul
Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, resulting in denial of service.
network
low complexity
hashicorp
7.5
2022-11-16 CVE-2022-3920 Missing Authorization vulnerability in Hashicorp Consul
HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI.
network
low complexity
hashicorp CWE-862
7.5
2022-09-23 CVE-2021-41803 Missing Authorization vulnerability in Hashicorp Consul
HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC.
network
low complexity
hashicorp CWE-862
7.1
2022-04-19 CVE-2022-29153 Server-Side Request Forgery (SSRF) vulnerability in multiple products
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints.
network
low complexity
hashicorp fedoraproject CWE-918
7.5
2021-12-12 CVE-2021-41805 Incorrect Authorization vulnerability in Hashicorp Consul
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control.
network
low complexity
hashicorp CWE-863
8.8
2021-09-07 CVE-2021-37219 Improper Certificate Validation vulnerability in Hashicorp Consul
HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation.
network
low complexity
hashicorp CWE-295
8.8
2021-07-17 CVE-2021-32574 Improper Certificate Validation vulnerability in Hashicorp Consul
HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encoded subject alternative name.
network
low complexity
hashicorp CWE-295
7.5
2021-07-17 CVE-2021-36213 Unspecified vulnerability in Hashicorp Consul
HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incorrectly fail open, allowing L4 traffic.
network
low complexity
hashicorp
7.5