Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2024-10006

Consul: L7 traffic intentions can be bypassed with crafted headers

Technology

HashiCorp Consul

CVSS Score

5.8 / 10.0

Affected Versions

Consul Community Edition 1.9.0 to 1.20.0; Consul Enterprise 1.9.0 up to 1.20.0, 1.19.2, 1.18.4 and 1.15.14

Upstream Fix

Community 1.20.1; Enterprise 1.20.1, 1.19.3, 1.18.5, 1.15.15

Published

October 30, 2024

OSSeva Coverage

Fixed upstream

Description

Headers in L7 traffic intentions could be crafted to bypass HTTP header-based access rules in the service mesh. HashiCorp scores it 8.3 as the CNA; the 5.8 score is NVD's.

Upstream record: NVD · CVE.org

Is your HashiCorp Consul deployment affected?

If you're running Consul Community Edition 1.9.0 to 1.20.0; Consul Enterprise 1.9.0 up to 1.20.0, 1.19.2, 1.18.4 and 1.15.14, you need this patch. Book a discovery call to get covered.