CVE-2021-41803: High severity hashicorp consul vulnerability
HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 did not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2.
Other sources
HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to interpolation and usage in JWT claim assertions with the auto config RPC. Fixed in 1.11.9, 1.12.5, and 1.13.2."
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this HashiCorp Consul vulnerability?
The vulnerability ID for this HashiCorp Consul vulnerability is CVE-2021-41803.
What is the severity of CVE-2021-41803?
The severity of CVE-2021-41803 is high with a severity value of 7.1.
Which versions of HashiCorp Consul are affected by CVE-2021-41803?
HashiCorp Consul versions 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 are affected by CVE-2021-41803.
How can I fix CVE-2021-41803?
You can fix CVE-2021-41803 by updating your HashiCorp Consul installation to version 1.11.9, 1.12.5, or 1.13.2.
Where can I find more information about CVE-2021-41803?
You can find more information about CVE-2021-41803 at the following references: [1](https://discuss.hashicorp.com/t/hcsec-2022-19-consul-auto-config-jwt-authorization-missing-input-validation/44627), [2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LYZOKMMVX4SIEHPJW3SJUQGMO5YZCPHC/), [3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XNF4OLYZRQE75EB5TW5N42FSXHBXGWFE/).