Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2024-10086

Consul: reflected cross-site scripting through a missing Content-Type header

Technology

HashiCorp Consul

CVSS Score

6.1 / 10.0

Affected Versions

Consul Community Edition 1.4.1 to 1.19.2; Consul Enterprise up to 1.19.2, 1.18.4 and 1.15.14

Upstream Fix

Community 1.20.0; Enterprise 1.20.0, 1.19.3, 1.18.5, 1.15.15

Published

October 30, 2024

OSSeva Coverage

Fixed upstream

Description

Server responses did not set an explicit Content-Type header, so user-provided input could be misinterpreted by a browser and lead to reflected cross-site scripting.

Upstream record: NVD · CVE.org

Is your HashiCorp Consul deployment affected?

If you're running Consul Community Edition 1.4.1 to 1.19.2; Consul Enterprise up to 1.19.2, 1.18.4 and 1.15.14, you need this patch. Book a discovery call to get covered.