Skip to content
consulGHSA-25gf-8qrr-g78r

Hashicorp Consul Missing SSL Certificate Validation

High7.5CVE-2021-32574 · Published Jul 19, 2021 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
< 1.10.11.10.1
Details and references

HashiCorp Consul before 1.10.1 (and Consul Enterprise) has Missing SSL Certificate Validation. xds does not ensure that the Subject Alternative Name of an upstream is validated.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-295
Also known as
BIT-consul-2021-32574, CVE-2021-32574, GO-2022-0894

More consul advisories

All
DateAdvisory
Jul 192021HashiCorp Consul L7 deny intention results in an allow action
CVE-2021-36213High7.5fixed in 1.10.1
Jul 282021Incorrect Authorization in HashiCorp Consul
CVE-2020-7955Medium5.3fixed in 1.6.3
Jun 232021Incorrect Permission Assignment for Critical Resource in Hashicorp Consul
CVE-2020-12797Medium5.3fixed in 1.6.6, 1.7.4
Sep 82021HashiCorp Consul Privilege Escalation Vulnerability
CVE-2021-37219High8.8fixed in 1.8.15, 1.9.9, 1.10.2
Sep 82021HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic.
CVE-2021-38698Medium6.5fixed in 1.8.15, 1.9.9, 1.10.2
May 182021Allocation of Resources Without Limits or Throttling in Hashicorp Consul
CVE-2020-13250High7.5fixed in 1.6.6, 1.7.4

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.