Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-10006

Опубликовано: 30 окт. 2024
Источник: redhat
CVSS3: 8.3

Описание

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.

A flaw was found in HashiCorp Consul and Consul Enterprise. The server response does not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and can lead to reflected cross-site scripting (XSS).

Отчет

This vulnerability is rated as important severity because HashiCorp Consul fails to set a Content-Type HTTP header, allowing user inputs to be misinterpreted and potentially leading to reflected cross-site scripting (XSS). This can compromise both confidentiality and integrity, posing a risk to user data and application security, which requires prompt remediation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Dev Spacesdevspaces/traefik-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-644
https://bugzilla.redhat.com/show_bug.cgi?id=2322858hashicorp/consul: consul: Consul L7 Intentions Vulnerable To Headers Bypass

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
больше 1 года назад

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.

CVSS3: 8.3
nvd
больше 1 года назад

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.

CVSS3: 8.3
debian
больше 1 года назад

A vulnerability was identified in Consul and Consul Enterprise (\u201c ...

CVSS3: 8.3
github
больше 1 года назад

Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability

CVSS3: 5.8
fstec
больше 1 года назад

Уязвимость инструмента настройки сервисов Consul Community Edition и Consul Enterprise, связанная с непринятием мер по нейтрализации заголовков HTTP для синтаксиса сценариев, позволяющая нарушителю получить достпу к конфиденциальной информации

8.3 High

CVSS3