CVE-2021-28156: High severity hashicorp consul vulnerability
Published Apr 20, 2021
·Updated
HashiCorp Consul Enterprise version 1.8.0 up to 1.9.4 audit log can be bypassed by specifically crafted HTTP events. Fixed in 1.9.5, and 1.8.10.
Affected Software
2 affected components
Hashicorp Consul>=1.8.0<1.8.10
Hashicorp Consul>=1.9.0<1.9.5
Event History
Apr 20, 2021
CVE Published
via MITRE·03:02 PM
Data Sourced
via MITRE·03:02 PM
Description
Frequently Asked Questions
1
What is CVE-2021-28156?
CVE-2021-28156 is a vulnerability in HashiCorp Consul Enterprise versions 1.8.0 up to 1.9.4 that allows the bypassing of the audit log through specially crafted HTTP events.
2
What is the severity of CVE-2021-28156?
The severity of CVE-2021-28156 is high, with a CVSS score of 7.5.
3
Which software versions are affected by CVE-2021-28156?
HashiCorp Consul Enterprise versions 1.8.0 up to 1.9.4 are affected by CVE-2021-28156.
4
How can I mitigate CVE-2021-28156?
To mitigate CVE-2021-28156, upgrade to HashiCorp Consul Enterprise version 1.8.10 or 1.9.5.
5
Where can I find more information about CVE-2021-28156?
You can find more information about CVE-2021-28156 on the HashiCorp discussion forum, Gentoo security advisories, and the HashiCorp blog.