CVE-2021-36213: High severity hashicorp consul vulnerability
HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware intention deny action cancels out, causing the intention to incorrectly fail open, allowing L4 traffic. Fixed in 1.9.8 and 1.10.1.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
CVE-2021-36213
What is the severity of CVE-2021-36213?
The severity of CVE-2021-36213 is high with a severity value of 7.5.
Which software versions are affected by CVE-2021-36213?
HashiCorp Consul and Consul Enterprise versions 1.9.0 through 1.10.0 are affected by CVE-2021-36213.
How can I fix CVE-2021-36213?
You can fix CVE-2021-36213 by upgrading to HashiCorp Consul and Consul Enterprise versions 1.9.8 or 1.10.1.
Where can I find more information about CVE-2021-36213?
You can find more information about CVE-2021-36213 at the following references: [Reference 1](https://discuss.hashicorp.com/t/hcsec-2021-16-consul-s-application-aware-intentions-deny-action-fails-open-when-combined-with-default-deny-policy/26855), [Reference 2](https://github.com/hashicorp/consul/releases/tag/v1.10.1), [Reference 3](https://security.gentoo.org/glsa/202208-09).