CVE-2024-10005: Consul L7 Intentions Vulnerable To URL Path Bypass
A vulnerability was identified in Consul and Consul Enterprise ("Consul") such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules.
Other sources
A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10005?
CVE-2024-10005 is a high-severity vulnerability as it allows for bypassing access rules based on HTTP request paths.
How do I fix CVE-2024-10005?
To fix CVE-2024-10005, update your Consul or Consul Enterprise installation to a version that addresses this vulnerability.
Which versions of Consul are affected by CVE-2024-10005?
CVE-2024-10005 affects multiple versions of Consul, specifically versions between 1.4.1 and 1.20.1.
What types of access rules are bypassed by CVE-2024-10005?
CVE-2024-10005 allows unauthorized access by bypassing HTTP request path-based access rules implemented in L7 traffic intentions.
Is CVE-2024-10005 a critical vulnerability in web applications?
Yes, CVE-2024-10005 is considered critical due to its potential impact on security in web application access control.