Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8h2g-r292-j8xh

Опубликовано: 19 июл. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

HashiCorp Consul L7 deny intention results in an allow action

In HashiCorp Consul before 1.10.1 (and Consul Enterprise), xds can generate a situation where a single L7 deny intention (with a default deny policy) results in an allow action.

Пакеты

Наименование

github.com/hashicorp/consul

go
Затронутые версииВерсия исправления

< 1.10.1

1.10.1

EPSS

Процентиль: 73%
0.00765
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incorrectly fail open, allowing L4 traffic. Fixed in 1.9.8 and 1.10.1.

CVSS3: 7.5
nvd
больше 4 лет назад

HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incorrectly fail open, allowing L4 traffic. Fixed in 1.9.8 and 1.10.1.

CVSS3: 7.5
debian
больше 4 лет назад

HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default de ...

EPSS

Процентиль: 73%
0.00765
Низкий

7.5 High

CVSS3