Skip to content
consulGHSA-8h2g-r292-j8xh

HashiCorp Consul L7 deny intention results in an allow action

High7.5CVE-2021-36213 · Published Jul 19, 2021 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
< 1.10.11.10.1
Details and references

In HashiCorp Consul before 1.10.1 (and Consul Enterprise), xds can generate a situation where a single L7 deny intention (with a default deny policy) results in an allow action.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity from
GitHub (reviewed advisory)
Also known as
BIT-consul-2021-36213, CVE-2021-36213, GO-2022-0895

More consul advisories

All
DateAdvisory
Jul 192021Hashicorp Consul Missing SSL Certificate Validation
CVE-2021-32574High7.5fixed in 1.10.1
Jul 282021Incorrect Authorization in HashiCorp Consul
CVE-2020-7955Medium5.3fixed in 1.6.3
Jun 232021Incorrect Permission Assignment for Critical Resource in Hashicorp Consul
CVE-2020-12797Medium5.3fixed in 1.6.6, 1.7.4
Sep 82021HashiCorp Consul Privilege Escalation Vulnerability
CVE-2021-37219High8.8fixed in 1.8.15, 1.9.9, 1.10.2
Sep 82021HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic.
CVE-2021-38698Medium6.5fixed in 1.8.15, 1.9.9, 1.10.2
May 182021Allocation of Resources Without Limits or Throttling in Hashicorp Consul
CVE-2020-13250High7.5fixed in 1.6.6, 1.7.4

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.