Skip to content
consulGHSA-rqjq-ww83-wv5c

Hashicorp Consul allows user with service:write permissions to patch remote proxy instances

High8.7CVE-2023-2816 · Published Jun 3, 2023 · updated Aug 20, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/consul
Go
>= 1.15.0, < 1.15.31.15.3
Details and references

Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-266
Also known as
BIT-consul-2023-2816, CVE-2023-2816, GO-2023-1828

More consul advisories

All
DateAdvisory
Jun 32023Hashicorp Consul vulnerable to denial of service
CVE-2023-1297Medium4.9fixed in 1.14.5, 1.15.3
Jun 92023HashiCorp Consul Incorrect Access Control vulnerability
CVE-2019-12291High7.5fixed in 1.5.1
Aug 92023Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
CVE-2023-3518High7.4fixed in 1.16.1
Mar 92023Consul Server Panic when Ingress and API Gateways Configured with Peering Connections
CVE-2023-0845Medium6.5fixed in 1.14.5
Nov 162022Missing Authorization in HashiCorp Consul
CVE-2022-3920High7.5fixed in 1.14.0
Jan 312024Denial of service in HashiCorp Consul
CVE-2020-25201High7.5fixed in 1.7.9, 1.8.5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.