First published: Tue Sep 07 2021(Updated: )
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Consul | <1.8.15 | |
HashiCorp Consul | <1.8.15 | |
HashiCorp Consul | >=1.9.0<1.9.9 | |
HashiCorp Consul | >=1.9.0<1.9.9 | |
HashiCorp Consul | >=1.10.0<1.10.2 | |
HashiCorp Consul | >=1.10.0<1.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-38698.
The title of the vulnerability is 'HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic.'
HashiCorp Consul and Consul Enterprise versions up to 1.8.15, 1.9.9, and 1.10.2 are affected by the vulnerability.
The severity of CVE-2021-38698 is medium.
To fix the vulnerability, update your HashiCorp Consul or Consul Enterprise installation to version 1.8.15, 1.9.9, or 1.10.2.