consulGHSA-25gf-8qrr-g78r
Hashicorp Consul Missing SSL Certificate Validation
High7.5CVE-2021-32574 · Published Jul 19, 2021 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/consul Go | < 1.10.1 | 1.10.1 |
Details and references
HashiCorp Consul before 1.10.1 (and Consul Enterprise) has Missing SSL Certificate Validation. xds does not ensure that the Subject Alternative Name of an upstream is validated.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-295
- Also known as
- BIT-consul-2021-32574, CVE-2021-32574, GO-2022-0894
More consul advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 192021 | HashiCorp Consul L7 deny intention results in an allow action CVE-2021-36213High7.5fixed in 1.10.1 | High7.5 | 1.10.1 |
| Jul 282021 | Incorrect Authorization in HashiCorp Consul CVE-2020-7955Medium5.3fixed in 1.6.3 | Medium5.3 | 1.6.3 |
| Jun 232021 | Incorrect Permission Assignment for Critical Resource in Hashicorp Consul CVE-2020-12797Medium5.3fixed in 1.6.6, 1.7.4 | Medium5.3 | 1.6.6, 1.7.4 |
| Sep 82021 | HashiCorp Consul Privilege Escalation Vulnerability CVE-2021-37219High8.8fixed in 1.8.15, 1.9.9, 1.10.2 | High8.8 | 1.8.15, 1.9.9, 1.10.2 |
| Sep 82021 | HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. CVE-2021-38698Medium6.5fixed in 1.8.15, 1.9.9, 1.10.2 | Medium6.5 | 1.8.15, 1.9.9, 1.10.2 |
| May 182021 | Allocation of Resources Without Limits or Throttling in Hashicorp Consul CVE-2020-13250High7.5fixed in 1.6.6, 1.7.4 | High7.5 | 1.6.6, 1.7.4 |