Vulnerability Report: GO-2024-2683
- CVE-2021-41803, GHSA-hr3v-8cp3-68rf
- Affects: github.com/hashicorp/consul
- Published: Apr 05, 2024
- Modified: May 20, 2024
HashiCorp Consul does not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC.
Affected Packages
-
PathGo VersionsSymbols
-
from v1.8.1 before v1.11.9, from v1.12.0 before v1.12.5, from v1.13.0 before v1.13.2
Aliases
References
- https://discuss.hashicorp.com/t/hcsec-2022-19-consul-auto-config-jwt-authorization-missing-input-validation/44627
- https://github.com/hashicorp/consul/pull/14577/commits/2c881259ce10e308ff03afc968c4165998fd7fee
- https://vuln.go.dev/ID/GO-2024-2683.json
Credits
- anonymous4ACL24
Feedback
See anything missing or incorrect?
Suggest an edit to this report.