HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2."
References
Link | Resource |
---|---|
https://www.hashicorp.com/blog/category/consul | Vendor Advisory |
https://discuss.hashicorp.com/t/hcsec-2022-19-consul-auto-config-jwt-authorization-missing-input-validation/44627 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-09-22 18:15
Updated : 2022-09-23 19:02
NVD link : CVE-2021-41803
Mitre link : CVE-2021-41803
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
hashicorp
- consul