ConsulGHSA-9rhf-q362-77mx
Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
High7.4CVE-2023-3518 · Published Aug 9, 2023 · updated Aug 7, 2026
A vulnerability was identified in Consul such that using JWT authentication for service mesh incorrectly allows/denies access regardless of service identities. This vulnerability, CVE-2023-3518, affects Consul 1.16.0 and was fixed in 1.16.1.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/consul Go | >= 1.16.0, < 1.16.1 | 1.16.1 |
Details and references
More Consul advisories
All Consul| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 312024 | Privilege Escalation in HashiCorp Consul | Medium6.5 | 1.6.10+2 more |
| Jan 312024 | Denial of service in HashiCorp Consul | High7.5 | 1.7.9+1 more |
| Jun 92023 | HashiCorp Consul Incorrect Access Control vulnerability | High7.5 | 1.5.1 |
| Jun 32023 | Hashicorp Consul vulnerable to denial of service | Medium4.9 | 1.14.5+1 more |
| Jun 32023 | Hashicorp Consul allows user with service:write permissions to patch remote proxy instances | High8.7 | 1.15.3 |
| Mar 92023 | Consul Server Panic when Ingress and API Gateways Configured with Peering Connections | Medium6.5 | 1.14.5 |