First published: Tue Apr 20 2021(Updated: )
HashiCorp Consul Enterprise version 1.8.0 up to 1.9.4 audit log can be bypassed by specifically crafted HTTP events. Fixed in 1.9.5, and 1.8.10.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Consul | >=1.8.0<1.8.10 | |
HashiCorp Consul | >=1.9.0<1.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28156 is a vulnerability in HashiCorp Consul Enterprise versions 1.8.0 up to 1.9.4 that allows the bypassing of the audit log through specially crafted HTTP events.
The severity of CVE-2021-28156 is high, with a CVSS score of 7.5.
HashiCorp Consul Enterprise versions 1.8.0 up to 1.9.4 are affected by CVE-2021-28156.
To mitigate CVE-2021-28156, upgrade to HashiCorp Consul Enterprise version 1.8.10 or 1.9.5.
You can find more information about CVE-2021-28156 on the HashiCorp discussion forum, Gentoo security advisories, and the HashiCorp blog.