Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-2816

Опубликовано: 02 июн. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.7

Описание

Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

kinetic

ignored

end of life, was needs-triage
lunar

DNE

mantic

ignored

end of life, was needs-triage

Показывать по

EPSS

Процентиль: 37%
0.00156
Низкий

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 8.7
nvd
больше 2 лет назад

Consul and Consul Enterprise allowed any user with service:write permissions to use Envoy extensions configured via service-defaults to patch remote proxy instances that target the configured service, regardless of whether the user has permission to modify the service(s) corresponding to those modified proxies.

CVSS3: 6.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 8.7
debian
больше 2 лет назад

Consul and Consul Enterprise allowed any user with service:write permi ...

CVSS3: 8.7
github
больше 2 лет назад

Hashicorp Consul allows user with service:write permissions to patch remote proxy instances

EPSS

Процентиль: 37%
0.00156
Низкий

8.7 High

CVSS3