consulGHSA-m69r-9g56-7mv8
HashiCorp Consul vulnerable to authorization bypass
Medium6.5CVE-2022-40716 · Published Sep 25, 2022 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/consul Go | < 1.11.9 | 1.11.9 |
| >= 1.12.0, < 1.12.5 | 1.12.5 | |
| >= 1.13.0, < 1.13.2 | 1.13.2 |
Details and references
HashiCorp Consul and Consul Enterprise versions prior to 1.11.9, 1.12.5, and 1.13.2 do not check for multiple SAN URI values in a CSR on the internal RPC endpoint, enabling leverage of privileged access to bypass service mesh intentions. A specially crafted CSR sent directly to Consul’s internal server agent RPC endpoint can include multiple SAN URI values with additional service names. This issue has been fixed in versions 1.11.9, 1.12.5, and 1.13.2. There are no known workarounds.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-252
- Also known as
- BIT-consul-2022-40716, CVE-2022-40716, GO-2022-1029
- nvd.nist.gov/vuln/detail/CVE-2022-40716
- github.com/hashicorp/consul/pull/14579
- github.com/hashicorp/consul/commit/8f6fb4f6fe9488b8ec37da71ac503081d7d3760b
- discuss.hashicorp.com
- discuss.hashicorp.com/t/hcsec-2022-20-consul-service-mesh-intention-bypass-with-malicious-certificate-signing-request/44628
- github.com/hashicorp/consul
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LYZOKMMVX4SIEHPJW3SJUQGMO5YZCPHC
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTE4ITXXPIWZEQ4HYQCB6N6GZIMWXDAI
More consul advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 252022 | HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions CVE-2021-41803High7.1fixed in 1.11.9, 1.12.5, 1.13.2 | High7.1 | 1.11.9, 1.12.5, 1.13.2 |
| Nov 162022 | Missing Authorization in HashiCorp Consul CVE-2022-3920High7.5fixed in 1.14.0 | High7.5 | 1.14.0 |
| May 242022 | HashiCorp Consul Cross-site Scripting vulnerability CVE-2020-25864Medium6.1fixed in 1.7.14, 1.8.10, 1.9.5 | Medium6.1 | 1.7.14, 1.8.10, 1.9.5 |
| May 142022 | HashiCorp Consul can use cleartext agent-to-agent RPC communication CVE-2018-19653Medium5.9fixed in 1.4.1 | Medium5.9 | 1.4.1 |
| May 132022 | HashiCorp Consul vulnerable to Origin Validation Error CVE-2019-9764High7.4fixed in 1.4.4 | High7.4 | 1.4.4 |
| May 132022 | HashiCorp Consul Access Restriction Bypass CVE-2019-8336High8.1fixed in 1.4.3 | High8.1 | 1.4.3 |