Bypassing HTTP Header Based Access Rules via L7 Traffic Intentions
CVE-2024-10006

5.8MEDIUM

Key Information:

Vendor
Hashicorp
Vendor
CVE Published:
30 October 2024

Summary

A security issue has been detected in Consul and Consul Enterprise that allows L7 traffic intentions to bypass access controls established through HTTP headers. This vulnerability could enable unauthorized access, disrupting the expected security posture of applications relying on these header-based rules. It's crucial for users to review and mitigate potential risks associated with this issue.

Affected Version(s)

Consul 64 bit 1.9.0 < 1.20.1

Consul Enterprise 64 bit 1.9.0 < 1.20.1

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.