CVE-2024-10006: Consul L7 Intentions Vulnerable To Headers Bypass
Published Oct 30, 2024
·Updated
A vulnerability was identified in Consul and Consul Enterprise ("Consul") such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.
Other sources
A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.
— MITRE
Affected Software
6 affected componentsFixes available
go/github.com/hashicorp/consul>=1.9.0<1.20.1
1.20.1
Hashicorp Consul>=1.4.1<1.20.1
Hashicorp Consul>=1.9.0<1.15.15
Hashicorp Consul>=1.18.0<1.18.5
Hashicorp Consul>=1.19.0<1.19.3
Hashicorp Consul=1.20.0
Event History
Oct 30, 2024
CVE Published
via MITRE·09:20 PM
Data Sourced
via MITRE·09:20 PM
DescriptionSeverityWeakness
Oct 31, 2024
Advisory Published
via GitHub·12:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-10006?
CVE-2024-10006 is classified as a medium severity vulnerability.
2
How do I fix CVE-2024-10006?
To fix CVE-2024-10006, upgrade Consul and Consul Enterprise to a version that is not affected.
3
What versions are affected by CVE-2024-10006?
CVE-2024-10006 affects Consul versions from 1.4.1 to 1.20.1.
4
What is the impact of CVE-2024-10006?
CVE-2024-10006 allows for HTTP header-based access rules to be bypassed, potentially compromising security.
5
Is CVE-2024-10006 specific to any deployment of Consul?
Yes, CVE-2024-10006 impacts both the community and enterprise versions of Consul.