Skip to content
consulGHSA-m69r-9g56-7mv8

HashiCorp Consul vulnerable to authorization bypass

Medium6.5CVE-2022-40716 · Published Sep 25, 2022 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
< 1.11.91.11.9
>= 1.12.0, < 1.12.51.12.5
>= 1.13.0, < 1.13.21.13.2
Details and references

HashiCorp Consul and Consul Enterprise versions prior to 1.11.9, 1.12.5, and 1.13.2 do not check for multiple SAN URI values in a CSR on the internal RPC endpoint, enabling leverage of privileged access to bypass service mesh intentions. A specially crafted CSR sent directly to Consul’s internal server agent RPC endpoint can include multiple SAN URI values with additional service names. This issue has been fixed in versions 1.11.9, 1.12.5, and 1.13.2. There are no known workarounds.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-252
Also known as
BIT-consul-2022-40716, CVE-2022-40716, GO-2022-1029

More consul advisories

All
DateAdvisory
Sep 252022HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions
CVE-2021-41803High7.1fixed in 1.11.9, 1.12.5, 1.13.2
Nov 162022Missing Authorization in HashiCorp Consul
CVE-2022-3920High7.5fixed in 1.14.0
May 242022HashiCorp Consul Cross-site Scripting vulnerability
CVE-2020-25864Medium6.1fixed in 1.7.14, 1.8.10, 1.9.5
May 142022HashiCorp Consul can use cleartext agent-to-agent RPC communication
CVE-2018-19653Medium5.9fixed in 1.4.1
May 132022HashiCorp Consul vulnerable to Origin Validation Error
CVE-2019-9764High7.4fixed in 1.4.4
May 132022HashiCorp Consul Access Restriction Bypass
CVE-2019-8336High8.1fixed in 1.4.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.