CVE-2023-3518: JWT Auth in L7 Intentions Allow For Mismatched Service Identity and JWT Providers for Access
A vulnerability was identified in Consul such that using JWT authentication for service mesh incorrectly allows/denies access regardless of service identities. This vulnerability, CVE-2023-3518, affects Consul 1.16.0 and was fixed in 1.16.1.
Other sources
HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities. Fixed in 1.16.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3518?
CVE-2023-3518 is a vulnerability in HashiCorp Consul and Consul Enterprise 1.16.0 that allows/denies access regardless of service identities when using JWT Auth for service mesh.
What is the severity of CVE-2023-3518?
CVE-2023-3518 has a severity rating of 7.4 (high).
How does CVE-2023-3518 affect HashiCorp Consul?
CVE-2023-3518 affects HashiCorp Consul and Consul Enterprise 1.16.0 versions when using JWT Auth for service mesh.
How can I fix CVE-2023-3518?
You can fix CVE-2023-3518 by upgrading to version 1.16.1 of HashiCorp Consul or Consul Enterprise.
Where can I find more information about CVE-2023-3518?
You can find more information about CVE-2023-3518 at the following link: https://discuss.hashicorp.com/t/hcsec-2023-25-consul-jwt-auth-in-l7-intentions-allow-for-mismatched-service-identity-and-jwt-providers/57004